4 comments

[ 0.22 ms ] story [ 12.5 ms ] thread
Ok so we are achieving interoperability by turning passkeys into strings.

You know what it's called when you store a secret string in your password manager?

A password.

From the linked spec,

> The authenticator data is a CBOR structure defined in the WebAuthn Level 3 specification, is returned by the getAuthenticatorData() method of the AuthenticatorAttestationResponse

From TFA,

> The payload is the authenticator data, a CTAP2 CBOR encoding of most of the credential record fields that is already specified by WebAuthn

Both link to the same section of the WebAuthn spec, §6.1 Authenticator Data[1]. Unless I'm missing something, that section is describing a custom binary format, not a CBOR encoding of data. (Though n.b. that one of the items contained by the outer custom binary format is CBOR, but the 37(ish) byte array itself is not CBOR.)

(…and it's stuff like that that just makes all of WebAuthn so impenetrable.)

[1]: https://www.w3.org/TR/webauthn-3/#sctn-authenticator-data

Having this in the Go standard library would be great. We are currently looking into implementing passkeys in our system using Go, is there any battle tested library?
Wondering how webauthn extensions will fit into this.

PRF for example, takes salts as inputs, if extensions are taken into consideration then it would need to capture input & client extension results too.