3 ms·
No, it is technically correct for nondiscoverable mode. Naturally, there should be low value in breaking the opacity of the stored key as it should be a private
by chimpoftheages 3y ago
No, it is technically correct for nondiscoverable mode. Naturally, there should be low value in breaking the opacity of the stored key as it should be a private key only used with the server that holds it. (But it would still mean many sites requesting that you replace any token found to have such a defect.)
- chimpoftheages 3y agoNot sure why reality is so controversial, here are references for anyone who wants to know how a (standard) unlimited fido hardware token works: https://security.stackexchange.com/questions/237271/where-are-fido-u2f-keys-stored https://security.stackexchange.com/questions/237271/where-ar... OTOH for resident keys they usually support 50-100.