upvote
The service can use the use the attestation feature to block passkey providers that are deemed undesirable for whatever reason. Hard not to see eventually only major providers being accepted, even things like Microsoft services requiring Microsoft Passkeys using the Microsoft Passkey App which you're now required to have on your phone. Or worse you now need Symantec Passkeys to login to Symantec services (using that example since I believe Symantec had a ToTP App you needed to reverse engineer to extract the ToTP seed from if you wanted to use a different Authenticator)
reply
If a service wanted to do that they could already do that, you even point to an example with a platform requiring their specific app to use the account. I've had banks which required me to have their own time-based code physical security tokens to log in, isn't that in the end the same?

This thing you're talking about isn't inherently a thing about passkeys. If a service wants to remove your ability to log in to their service they can do it in a million different ways.

Also, the above poster said:

> deplatform you with a single click across all your accounts

"They" could do it across all your accounts with a single click. If service A decides to require attestation, how is that now affecting all my accounts?

reply
Unfortunately the US has willfully destroyed a significant amount of goodwill with citizens of their NATO allies. Due to aggressive rhetoric we are forced to look at the risks differently now.

Further centralization on US services for something that already works fine (like 2FA) is unnecessary risk.

reply
I agree the US has torched a lot of international goodwill.

Once again how does this relate to passkeys? You don't have to use US companies to use passkeys. There are European providers of authenticators. What country is Yubico based out of again? Just picking one example, there are others.

reply