TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Would injecting my key material in FIDO authenticator undermine its attestation?

1 点作者 dimonomid超过 5 年前
We&#x27;re discussing proposals to backup FIDO2 authenticator, and Emil from Yubico mentioned that allowing the user to inject their own key material &quot;undermines device attestation, which would likely disqualify those authenticators from high-security applications like financial institutions.&quot;<p>I&#x27;m wondering, is that actually the case?<p>To me, not allowing me to inject my own key material couldn&#x27;t be an advantage, because I have no guarantee that the vendor didn&#x27;t keep the copy of it for whatever reason. And if I&#x27;m able to set key material, then there is no need to trust the vendor, at least not to the same extent by far.<p>But I&#x27;m wondering whether I&#x27;m overlooking something.<p>The proposal is being discussed here https:&#x2F;&#x2F;gist.github.com&#x2F;emlun&#x2F;4c3efd99a727c7037fdb86ffd43c020d#gistcomment-3073739

暂无评论

暂无评论