3 ms·
For those wondering: the local threat here is a malicious extension can modify the function of navigator.credentials. While not malicious, this has been shown
by cendyne 4y ago
For those wondering: the local threat here is a malicious extension can modify the function of navigator.credentials.
While not malicious, this has been shown to be possible by 1Password. See https://www.future.1password.com/passkeys/ https://www.future.1password.com/passkeys/ and I have confirmed it is possible to modify this function.
JavaScript can be monkey patched, in some ways this is great for polyfills. For other cases this can be a threat.
If browsers had an explicit mechanism to register extension provided Authenticators and locked down a way to modify the original navigator credentials interface, then we may be able to protect the "first" bytes that come back from the authenticator to the application.