Opaque, Interoperable Passkey Records (and a Go API)
gnabgib
30 points
5 comments
July 20, 2026
Related Discussions
Found 5 related stories in 310.0ms across 14,369 title embeddings via pgvector HNSW
- Show HN: Keeper – embedded secret store for Go (help me break it) babawere · 59 pts · April 10, 2026 · 49% similar
- OpenAI mandates hardware-backed passkeys for Trusted Access Cyber members speckx · 54 pts · July 14, 2026 · 45% similar
- Show HN: Open-source API Key server written in Go by Ory leetvibecoder · 31 pts · June 11, 2026 · 45% similar
- Show HN: CipherStash Stack – Data Level Access Control in TS/JS dandraper · 11 pts · May 21, 2026 · 44% similar
- Pact: Anonymous Credentials for the Web kevincox · 53 pts · June 23, 2026 · 43% similar
Discussion Highlights (2 comments)
cadamsdotcom
Ok so we are achieving interoperability by turning passkeys into strings. You know what it's called when you store a secret string in your password manager? A password.
deathanatos
From the linked spec, > The authenticator data is a CBOR structure defined in the WebAuthn Level 3 specification, is returned by the getAuthenticatorData() method of the AuthenticatorAttestationResponse From TFA, > The payload is the authenticator data, a CTAP2 CBOR encoding of most of the credential record fields that is already specified by WebAuthn Both link to the same section of the WebAuthn spec, §6.1 Authenticator Data[1]. Unless I'm missing something, that section is describing a custom binary format, not a CBOR encoding of data. (Though n.b. that one of the items contained by the outer custom binary format is CBOR, but the 37(ish) byte array itself is not CBOR.) (…and it's stuff like that that just makes all of WebAuthn so impenetrable.) [1]: https://www.w3.org/TR/webauthn-3/#sctn-authenticator-data