Post

Replies

Boosts

Views

Activity

Comment on Can a third-party credential provider participate in the FIDO2 hybrid (cross-device) transport as the authenticator?
Hi! Not fully clear what this means for my case (same as OP's), sorry Will a device-bound key get flat-out rejected by completeRegistrationRequest, or just quietly never surface where Hybrid offers passkeys? Nothing in the API seems to check key provenance: I build authenticatorData myself, flags included Is this actually enforced, or more "unsupported, please don't"? Also: does legitimate third-party sync (not iCloud) count as a real passkey for this purpose?
Topic: Privacy & Security SubTopic: General Tags:
Aug ’26
Comment on Can a third-party credential provider participate in the FIDO2 hybrid (cross-device) transport as the authenticator?
Hi! Not fully clear what this means for my case (same as OP's), sorry Will a device-bound key get flat-out rejected by completeRegistrationRequest, or just quietly never surface where Hybrid offers passkeys? Nothing in the API seems to check key provenance: I build authenticatorData myself, flags included Is this actually enforced, or more "unsupported, please don't"? Also: does legitimate third-party sync (not iCloud) count as a real passkey for this purpose?
Topic: Privacy & Security SubTopic: General Tags:
Aug ’26
Comment on Can a third-party credential provider participate in the FIDO2 hybrid (cross-device) transport as the authenticator?
Hi! Not fully clear what this means for my case (same as OP's), sorry Will a device-bound key get flat-out rejected by completeRegistrationRequest, or just quietly never surface where Hybrid offers passkeys? Nothing in the API seems to check key provenance: I build authenticatorData myself, flags included Is this actually enforced, or more "unsupported, please don't"? Also: does legitimate third-party sync (not iCloud) count as a real passkey for this purpose?
Topic: Privacy & Security SubTopic: General Tags:
Aug ’26
Comment on Can a third-party credential provider participate in the FIDO2 hybrid (cross-device) transport as the authenticator?
Hi! Not fully clear what this means for my case (same as OP's), sorry Will a device-bound key get flat-out rejected by completeRegistrationRequest, or just quietly never surface where Hybrid offers passkeys? Nothing in the API seems to check key provenance: I build authenticatorData myself, flags included Is this actually enforced, or more "unsupported, please don't"? Also: does legitimate third-party sync (not iCloud) count as a real passkey for this purpose?
Topic: Privacy & Security SubTopic: General Tags:
Replies
Boosts
Views
Activity
Aug ’26
Comment on Can a third-party credential provider participate in the FIDO2 hybrid (cross-device) transport as the authenticator?
Hi! Not fully clear what this means for my case (same as OP's), sorry Will a device-bound key get flat-out rejected by completeRegistrationRequest, or just quietly never surface where Hybrid offers passkeys? Nothing in the API seems to check key provenance: I build authenticatorData myself, flags included Is this actually enforced, or more "unsupported, please don't"? Also: does legitimate third-party sync (not iCloud) count as a real passkey for this purpose?
Topic: Privacy & Security SubTopic: General Tags:
Replies
Boosts
Views
Activity
Aug ’26
Comment on Can a third-party credential provider participate in the FIDO2 hybrid (cross-device) transport as the authenticator?
Hi! Not fully clear what this means for my case (same as OP's), sorry Will a device-bound key get flat-out rejected by completeRegistrationRequest, or just quietly never surface where Hybrid offers passkeys? Nothing in the API seems to check key provenance: I build authenticatorData myself, flags included Is this actually enforced, or more "unsupported, please don't"? Also: does legitimate third-party sync (not iCloud) count as a real passkey for this purpose?
Topic: Privacy & Security SubTopic: General Tags:
Replies
Boosts
Views
Activity
Aug ’26