TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Would injecting my key material in FIDO authenticator undermine its attestation?

1 pointsby dimonomidover 5 years ago
We&#x27;re discussing proposals to backup FIDO2 authenticator, and Emil from Yubico mentioned that allowing the user to inject their own key material &quot;undermines device attestation, which would likely disqualify those authenticators from high-security applications like financial institutions.&quot;<p>I&#x27;m wondering, is that actually the case?<p>To me, not allowing me to inject my own key material couldn&#x27;t be an advantage, because I have no guarantee that the vendor didn&#x27;t keep the copy of it for whatever reason. And if I&#x27;m able to set key material, then there is no need to trust the vendor, at least not to the same extent by far.<p>But I&#x27;m wondering whether I&#x27;m overlooking something.<p>The proposal is being discussed here https:&#x2F;&#x2F;gist.github.com&#x2F;emlun&#x2F;4c3efd99a727c7037fdb86ffd43c020d#gistcomment-3073739

no comments

no comments