3 ms·
Not finding fault. The point of Webauthn is convenience - but the trade off is that if CTAP is compromised, it’s convenient for the attacker too.
by not_that_noob 8y ago
Not finding fault. The point of Webauthn is convenience - but the trade off is that if CTAP is compromised, it’s convenient for the attacker too.
- StavrosK 8y agoI don't see how that's different from passwords, though. If your password gets compromised, it's game over as well, and it's much easier to compromise that.