3 ms·
hah you are right. They address this concern specifically in 2.1: >DBSC is not designed to give hosts any sort of guarantee about the specific device a session
by no_time 1y ago
hah you are right. They address this concern specifically in 2.1:
>DBSC is not designed to give hosts any sort of guarantee about the specific device a session is registered to, or the state of this device.
Nevermind then. Also makes it more or less useless as a security measure but atleast not outright harmful like the famous WEI proposal.
- fc417fc802 1y ago> makes it more or less useless as a security measure Define "security". This is incredibly useful for mitigating bearer token exfiltration which is the stated purpose. It's also the same way ssh keypairs work and those are clearly much more secure than passwords. It's only "insecure" from the perspective of a service host who wants to exert control over end users. Even webauthn leaves attestation as an optional thing. Even in the case that the service operator requires it, so long as they don't engage in vendor whitelisting you can create a snakeoil authority on the fly. The main advantage this has over webauthn is that it is so much simpler.