<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Passkeys are just sparkling TLS client certs]]></title><description><![CDATA[<p>Passkeys are just sparkling TLS client certs</p>]]></description><link>https://board.circlewithadot.net/topic/0a52f06a-6cd1-4308-b84d-b45ac843e084/passkeys-are-just-sparkling-tls-client-certs</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 08:29:18 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/0a52f06a-6cd1-4308-b84d-b45ac843e084.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 26 Apr 2026 00:04:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Mon, 27 Apr 2026 10:39:56 GMT]]></title><description><![CDATA[<p><span><a href="https://social.lkw.tf/profile/isithran">@<span>isithran</span></a></span> <span><a href="/user/xssfox%40cloudisland.nz">@<span>xssfox</span></a></span> not quite, they can be synced^ and transferred*</p>]]></description><link>https://board.circlewithadot.net/post/https://cloudisland.nz/users/yaakov/statuses/116476241304862308</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cloudisland.nz/users/yaakov/statuses/116476241304862308</guid><dc:creator><![CDATA[yaakov@cloudisland.nz]]></dc:creator><pubDate>Mon, 27 Apr 2026 10:39:56 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Mon, 27 Apr 2026 10:21:21 GMT]]></title><description><![CDATA[<span><a href="https://cloudisland.nz/users/yaakov">@<span>yaakov</span></a></span> <span><a href="/user/xssfox%40cloudisland.nz">@<span>xssfox</span></a></span> this, with the notable limitation that private keys are now device bound <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f63f.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--crying_cat_face" style="height:23px;width:auto;vertical-align:middle" title="😿" alt="😿" />]]></description><link>https://board.circlewithadot.net/post/https://social.lkw.tf/objects/697d94f6-1069-ef38-a172-cf5357956005</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.lkw.tf/objects/697d94f6-1069-ef38-a172-cf5357956005</guid><dc:creator><![CDATA[isithran@social.lkw.tf]]></dc:creator><pubDate>Mon, 27 Apr 2026 10:21:21 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Mon, 27 Apr 2026 08:50:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/xssfox%40cloudisland.nz">@<span>xssfox</span></a></span> : no they're not.</p><p>IIRC client certs are bound to the TLS channel, while passkeys are bound to the domain name.</p><p>Passkeys do not protect against DNS domain takeovers or BGP hijacks (where a malicious website hijacks the domain name and obtains a valid https website certificate).</p><p>OTOH if your browser has a TLS connection to a MitM proxy such as Cloudflare or Fastly, you're dead in the water anyway.<br /> </p><p><a href="https://todon.nl/tags/TLS" rel="tag">#<span>TLS</span></a> <a href="https://todon.nl/tags/MitM" rel="tag">#<span>MitM</span></a> <a href="https://todon.nl/tags/AitM" rel="tag">#<span>AitM</span></a> <a href="https://todon.nl/tags/Passkeys" rel="tag">#<span>Passkeys</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://todon.nl/users/ErikvanStraten/statuses/116475810140144254</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://todon.nl/users/ErikvanStraten/statuses/116475810140144254</guid><dc:creator><![CDATA[erikvanstraten@todon.nl]]></dc:creator><pubDate>Mon, 27 Apr 2026 08:50:17 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Mon, 27 Apr 2026 07:07:33 GMT]]></title><description><![CDATA[<p><span><a href="https://aus.social/@jpm">@<span>jpm</span></a></span> <span><a href="/user/xssfox%40cloudisland.nz">@<span>xssfox</span></a></span> Lotus Notes is usable?  That's not what I remember</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.radio/users/EI3JDB/statuses/116475406181631972</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.radio/users/EI3JDB/statuses/116475406181631972</guid><dc:creator><![CDATA[ei3jdb@mastodon.radio]]></dc:creator><pubDate>Mon, 27 Apr 2026 07:07:33 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Mon, 27 Apr 2026 05:35:09 GMT]]></title><description><![CDATA[<span><a href="/user/xssfox%40cloudisland.nz" rel="ugc">@<span>xssfox</span></a></span> at least there's no PKI attached to them (I THINK?????????)]]></description><link>https://board.circlewithadot.net/post/https://pleroma.envs.net/objects/ca0e3c21-b559-4aa3-be8c-1b0931472ded</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://pleroma.envs.net/objects/ca0e3c21-b559-4aa3-be8c-1b0931472ded</guid><dc:creator><![CDATA[hellbeast@pleroma.envs.net]]></dc:creator><pubDate>Mon, 27 Apr 2026 05:35:09 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Mon, 27 Apr 2026 03:51:21 GMT]]></title><description><![CDATA[<p>I love how this annoys or clicks with people in different ways</p>]]></description><link>https://board.circlewithadot.net/post/https://cloudisland.nz/users/xssfox/statuses/116474634670299412</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cloudisland.nz/users/xssfox/statuses/116474634670299412</guid><dc:creator><![CDATA[xssfox@cloudisland.nz]]></dc:creator><pubDate>Mon, 27 Apr 2026 03:51:21 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Mon, 27 Apr 2026 03:47:18 GMT]]></title><description><![CDATA[<p><span><a href="/user/xssfox%40cloudisland.nz">@<span>xssfox</span></a></span> shutup shut up SHUT UP SHUT</p><p>/lh</p>]]></description><link>https://board.circlewithadot.net/post/https://furry.engineer/users/AVincentInSpace/statuses/116474618740398636</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://furry.engineer/users/AVincentInSpace/statuses/116474618740398636</guid><dc:creator><![CDATA[avincentinspace@furry.engineer]]></dc:creator><pubDate>Mon, 27 Apr 2026 03:47:18 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Sun, 26 Apr 2026 23:22:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/xssfox%40cloudisland.nz">@<span>xssfox</span></a></span> worse, since their cryptographic auth is one-time, exchanged for a long-lived stealable cookie</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/rileywd/statuses/116473579380878236</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/rileywd/statuses/116473579380878236</guid><dc:creator><![CDATA[rileywd@mastodon.social]]></dc:creator><pubDate>Sun, 26 Apr 2026 23:22:59 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Sun, 26 Apr 2026 10:15:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/xssfox%40cloudisland.nz">@<span>xssfox</span></a></span> I thought sparkling Smart Cards</p>]]></description><link>https://board.circlewithadot.net/post/https://cloudisland.nz/users/yaakov/statuses/116470482235759814</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cloudisland.nz/users/yaakov/statuses/116470482235759814</guid><dc:creator><![CDATA[yaakov@cloudisland.nz]]></dc:creator><pubDate>Sun, 26 Apr 2026 10:15:20 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Sun, 26 Apr 2026 00:41:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/xssfox%40cloudisland.nz">@<span>xssfox</span></a></span> With landlords</p>]]></description><link>https://board.circlewithadot.net/post/https://chitter.xyz/users/faoluin/statuses/116468227705354345</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chitter.xyz/users/faoluin/statuses/116468227705354345</guid><dc:creator><![CDATA[faoluin@chitter.xyz]]></dc:creator><pubDate>Sun, 26 Apr 2026 00:41:59 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Sun, 26 Apr 2026 00:12:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/xssfox%40cloudisland.nz">@<span>xssfox</span></a></span> with TOFU</p>]]></description><link>https://board.circlewithadot.net/post/https://tacobelllabs.net/users/arrjay/statuses/116468112217830279</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tacobelllabs.net/users/arrjay/statuses/116468112217830279</guid><dc:creator><![CDATA[arrjay@tacobelllabs.net]]></dc:creator><pubDate>Sun, 26 Apr 2026 00:12:36 GMT</pubDate></item><item><title><![CDATA[Reply to Passkeys are just sparkling TLS client certs on Sun, 26 Apr 2026 00:05:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/xssfox%40cloudisland.nz">@<span>xssfox</span></a></span> with vendor-lockin</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/fogti/statuses/116468082634201490</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/fogti/statuses/116468082634201490</guid><dc:creator><![CDATA[fogti@chaos.social]]></dc:creator><pubDate>Sun, 26 Apr 2026 00:05:05 GMT</pubDate></item></channel></rss>