Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, its called "hybrid transport", and its a flow where a laptop presents a QR code to a mobile phone, who then sets up a BLE connection for one time use of the passkey.

https://www.corbado.com/blog/webauthn-passkey-qr-code

(Not sure how the "cloud assisted" part of caBLE works)



So... you need to carry two electronic devices for this so-called security solution?


No… you can also sync with iCloud Passwords, or use a hardware token, like a Yubikey.


So a Yubikey is not an electronic device that you need to carry?

iCloud Passwords don't run on an iPhone that is an electronic device that you need to carry?

Those electronic devices that you mention don't each store the keys in a proprietary format and you can't access them without the vendor's cooperation - i.e. vendor lock in?


>Those electronic devices that you mention don't each store the keys in a proprietary format and you can't access them without the vendor's cooperation - i.e. vendor lock in?

Passkey portability is being worked on. Here is the draft of the open standard:

https://github.com/fido-alliance/credential-exchange-feedbac...

News article: https://www.theverge.com/2024/10/15/24270875/password-manage...


BLE seems to be a different way to authenticate than QR codes. Desktop computers may often not have Bluetooth chips.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: