3 ms·
Does this passwordless future still involve getting a cookie in your browser that can be stolen and used from an attackers machine? If so, we still have a probl
by eyeareque 4y ago
Does this passwordless future still involve getting a cookie in your browser that can be stolen and used from an attackers machine? If so, we still have a problem to fix.
- stavros 4y agoHow would you propose doing sessions instead?
- eyeareque 4y agoThis seemed promising but it doesn’t look like it had any traction https://www.rfc-editor.org/rfc/rfc8471 https://www.rfc-editor.org/rfc/rfc8471
- madjam002 4y agoAFAIK Token binding was designed to solve this problem, but was removed from Google Chrome for being too complicated for the benefits it brought. Not sure if there is anything else in the works.