3 ms·
The author points out that you can detect this by finding keys that have an unusually high signature counter. It becomes one signal amongst many, including IP a
by gtsteve 5y ago
The author points out that you can detect this by finding keys that have an unusually high signature counter. It becomes one signal amongst many, including IP addresses, user agents, etc that are correlated with bot-like activity. You still also get to track other things such as whether the user is moving their mouse and how realistic that looks, as well as past behaviour from that user.
I guess in the edge case where you are a legitimate but very heavy user of u2f keys and you happen to share one with a batch that is being abused for bad activity... you just get shown a regular captcha and continue with your day I guess.
The design of the system will surely reduce the percentage of people that get that experience however.
- no_time 5y ago>The author points out that you can detect this by finding keys that have an unusually high signature counter. Ah that makes sense. No evil fun for me then :^(