Skip to content

Comment on Pass the Passkey: A Novel Attack Surface in Passwordless Authenticationparent

Comments

While you are technically correct, I know for sure that an RP might be unaware that not requiring user verification means Chrome is free to let malware steal the passkey... (Our Keycloak is (mis)configured like that.)

Do you happen to know if this is because Google had to implement sync in userspace, or is it an inherent limitation that could also affect Apple?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.