I think all the fuckups of webauthn can be traced back to the fact that the underlying protocol is very simple and therefore enables a wide ecosystem of authenticators, but the companies that brought it to the web wanted to have absolute control over what authenticators users use.
add a skeleton here at some point
19 days ago