fragmede 11 months ago

Then how come KeePassXC has them?

  • indigo945 11 months ago

    The linked blog post explains it. The spec can be implemented by open source software, but the upcoming (or now current?) update to the spec enables attestation, that is, it allows the auth provider to cryptographically verify which implementation the client is using. Under this scheme, auth providers can simply choose to no longer support open source implementations like KeePassXC, and since the spec authors have already claimed that KeePassXC is "non-compliant" because it doesn't ask for a PIN on every auth request, it seems likely that that would happen.

    • fragmede 11 months ago

      Yes but it seems like KeyPassXC could just ask for PIN on every auth request to satisfy that requirement, without having to close their source.

      • reddalo 11 months ago

        What if I don't want KeyPassXC to ask me for a PIN every time? I can modify its source code and nobody can stop me.

        • pbhjpbhj 11 months ago

          Then your version of KeyPass will not be signed and won't pass TPM checks and so the banking app will refuse to run unless you open the signed version?

    • tadfisher 11 months ago

      Attestation is dead outside of corporate environments. Apple will not implement it except through MDM.

      • freedomben 11 months ago

        Isn't PAT apple implementing attestation for everyone?

      • GoblinSlayer 11 months ago

        Apple will implement it.

        • tadfisher 11 months ago

          Source? That is surprising news.