4 ms·
The attack you're describing doesn't require wifi. If the victim visits the attacker's page, the attacker page is free to request signatures (also non-presence-
by robryk 5y ago
The attack you're describing doesn't require wifi. If the victim visits the attacker's page, the attacker page is free to request signatures (also non-presence-attesting signatures) from the key. This can be used to send data to the key (in the nonce) and from the key (the signature is nondeterministic). I don't know if this can be done without user's awareness in the new web api for security keys, though.