Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you rely on Attestation, all you have to do is use Private Access Tokens: https://developer.apple.com/news/?id=huqjyh7k


That's (anonymous) device attestation, not authentication key/credential attestation. Two completely different use cases.

One prevents against spam/bots, the other prevents against users getting phished/scammed into registering an attacker's credential on their account (or using an insecure credential that can later be phished/hacked, e.g. because it's not hardware-bound and easily exportable).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: