I agree with you that the attestation as it stands right now does not serve a useful purpose in the case of passkeys and should be improved upon. However, shouldn't Apple refrain from tampering with how attestations are used in the middle? With the advent of third-party credential provider extension, there may be some attestation types other than "none" that have a sensible use. For Apple to prevent such uses outright does not seem to be WebAuthn specification complaint either.
Topic:
Safari & Web
SubTopic:
General
Tags: