4 ms·
Your phone holds the passwords for the websites but they passwords never get presented to the user. FaceID is just used to unlock the password store. You would
by Polylactic_acid 6y ago
Your phone holds the passwords for the websites but they passwords never get presented to the user. FaceID is just used to unlock the password store. You would have to steal a phone and trick faceid on the phone to gain access to someones account.
- mrwnmonm 6y agoSorry, I still don't see the improvement here, doesn't that already happen using chrome for example, or Touch ID with 1password? (I think IOS has that too)
- Rafert 6y agoThat's correct, but 1Password stores a static secret (the password) and this may be re-used by less security-minded folks as you probably know. WebAuthn servers only store a public key which is useless in case the server gets compromised. WebAuthn also is phsihing proof by having browsers verify the domain the credentials are used for. See more at https://webauthn.guide/ https://webauthn.guide/
- mrwnmonm 6y agoThanks for the link <3