Does Apple still prevent packed attestation from being used with its third party passkey credential provider API?
Attestation formats are well-defined in both the WebauthN 3 working draft from W3C and the proposed CTAP 2.2 standard from FIDO.
The attestation formats have not meaningfully changed, in fact the FIDO CTAP 2.2 proposed standard references the current WebAuthN 2 attestation formats.
The standards state that authenticators SHOULD implement attestation. Apple's artificial restrictions prevent development of an authenticator that conforms to the WebauthN/CTAP standards.
Topic:
App & System Services
SubTopic:
Core OS
Tags: