logoalt Hacker News

Tharreyesterday at 7:41 PM1 replyview on HN

Read my previous comment again. Passkeys are nice, but they don't solve the problem that's being discussed here.


Replies

Retr0idyesterday at 7:48 PM

I'm not sure if you understand what makes passkeys phishing-resistant?

The backdoored version of the app would need to have a different app ID, since the attacker does not have the legitimate publisher's signing keys. So the OS shouldn't let it access the legitimate app's credentials.

show 2 replies