3 ms·
All forms of FIDO2 authentication do fundamentally rely on being able to trust the browser to not misrepresent the "relying party" (the RP, aka the registered d
by BillinghamJ 3y ago
All forms of FIDO2 authentication do fundamentally rely on being able to trust the browser to not misrepresent the "relying party" (the RP, aka the registered domain, github.com in this case)
They are phishing resistant, even when using the cross-device QR code thing, but that does rely on some base level of trust in the user agent
At the end of the day though, if the browser is the malicious actor, there's simply nothing you can do. That is not a realistic or defensible scenario in most threat models
Passkeys do represent an enormous improvement in security for users, including in the scenario you've highlighted
I know in traditional auth setups, that kind of situation does tend to invite additional concerns, but (again assuming you trust the user agent) FIDO2 still provides full protection when that's happening