3 ms·
Correct me if I'm wrong, but won't WebAuthn with hardware tokens still be vulnerable to MITM phishing attacks? Ones where the attacker sets up a convincingly fa
by qqii 5y ago
Correct me if I'm wrong, but won't WebAuthn with hardware tokens still be vulnerable to MITM phishing attacks? Ones where the attacker sets up a convincingly fake website and forwards the signature to the actual server?
- BenjiWiebe 5y agoThe signature will be for the convincing fake and won't be valid for the real site. Plus, your hardware key won't even recognize the fake site as an enrolled site, and won't even generate a signature for the fake site! I think that's mostly right anyways. There's a very helpful explanation somewhere upthread and that's what I understood from it.