logoalt Hacker News

zdp7yesterday at 5:34 PM2 repliesview on HN

There is security value. A passkey will not work anywhere except the actual website. Fake look a like sites can't get the credentials. Evidently they can trick you into authorizing their device.


Replies

harshrealityyesterday at 6:08 PM

That's also how any good password manager works. You'd have to manually copy-paste the password to get around the same-site fill restriction (whether it's autofill or manual fill).

thyristanyesterday at 6:04 PM

Sure? MitM isn't a new kind of attack, and I'd be surprised if the ball-of-wax-and-javascript that is WebAuthn isn't vulnerable to that...

show 1 reply