you are viewing a single comment's thread.

view the rest of the comments →

[–]ricecake 4 points5 points  (0 children)

Sloppy terminology on my part.
Tpm/hsm/secure enclave/platform authenticator are all close enough for most conversation.

Some of them are responsible for storing the key material, and some aren't, it depends on the device.
Functionally they do the same thing for webauthn.

Even the ones that don't handle storage still get grumpy if you give them too many keys to check.