3 ms·
My example is still just as good if the ID holder is complicit. But also, this on-device fingerprint MFA would presumably be fairly bypassable. E.g. just glit
by nullc 28d ago
My example is still just as good if the ID holder is complicit.
But also, this on-device fingerprint MFA would presumably be fairly bypassable. E.g. just glitch the device to extract the private key. ... and of course all the power hungry / extra complex ZKP machinery means less resources spent on preventing glitch attacks.
- Spivak 14d agoAlso if you enforce the use of Yubikey or a similar DRM protected device then we're back to the user not actually being able to own/control their key. And if you don't it's a second password which can be shared out. "Just use existing OTP" is a model that assumes that people actually want to protect their credentials. This is a Netflix password sharing situation and OTP didn't solve it.