4 ms·
WebAuthn protects the sign in, but malware can still steal the resulting cookies. DBSC protects the sign in _session_. (It should stand for Don’t Bother Steali
by agl 1y ago
WebAuthn protects the sign in, but malware can still steal the resulting cookies. DBSC protects the sign in _session_. (It should stand for Don’t Bother Stealing Cookies.)
- mmis1000 1y agoIf you read the proposal carefully. this api is used to refresh/revalidate extremely short lived cookie. not replace cookie itself. Which you can already do with webauthn
- nicce 1y agoMaybe there is an assumption that this is easier to push through for masses because the UX is better. (no phone, no physical key required)
- ximm 1y agoWebauthn always requires a user presence check though.
- mmis1000 1y agoSeems the whole proposal exists solely because they are unwilling to add a "silence" option to webauthn. I am confused about the decision though. https://github.com/w3c/webauthn/issues/199#issuecomment-2669744016 https://github.com/w3c/webauthn/issues/199#issuecomment-2669...