4 ms·
Webauthn public key for pornhub gets signed by chase and authenticated on pornhub along with chases signature. I give that to you, chases signature is valid bu
by jwally 1y ago
Webauthn public key for pornhub gets signed by chase and authenticated on pornhub along with chases signature.
I give that to you, chases signature is valid but you can't perform webauthn auth.
Thats why you cant sell spun up credentials en masse.
- LamaOfRuin 1y agoYou've said this a couple times, but... it's not true? Webauthn allows for software authenticators and there is nothing to stop you from transferring it complete with keys to someone else.
- jwally 1y agoFair point...but worth the effort? Also, what if the bank signs your ip-address and user-agent-header as part of their payload back to the RP? That's like mission-impossible / hack into Langely level of effort to get into pornhub, no?
- jeroenhd 1y agoMy Bitwarden extension stores my webauthn keys and those keys work on any device I have Bitwarden unlocked on. I could definitely share any webauthn account with anyone of my choice if I wanted to. Just store the generated key in a shared webauthn vault. You can go spec-incompliant and tell the browser to only accept certain types of hardware to store your credential, but unless the entire ecosystem maintains lists of compromised hardware and blocks half the desktop user base for defeated TPM mechanisms, you're going to have to deal with spoofed clients. The only reason spoofed TPM/hardware backed credential stores aren't a problem for webauthn right now is that there is no need to spoof them at the moment.