3 ms·
Fair point on the timeout. Webauthn ties the public keys to your device; chases signature of it verifies it; your webauthn authentication of chases signed vers
by jwally 1y ago
Fair point on the timeout.
Webauthn ties the public keys to your device; chases signature of it verifies it; your webauthn authentication of chases signed version of your key proves it was you the whole time.
Nested dolls/Chain of custody.
What am I overlooking?
- sandeepkd 1y agoChase signed a key that was provided to it, and chase verified for that user who logged in to chase. For whom the key was generated for and who entered in the chase site/api can be altogether two different entities. This is where it breaks. And chase like banks do not have any practical reason/motivation to provide such a functionality where they are vouching for something but dont really control how that information is used. The legal would never approve it, there is nothing but risk in it for them.