Passkeys are just sparkling TLS client certs
-
Passkeys are just sparkling TLS client certs
@xssfox With landlords
-
Passkeys are just sparkling TLS client certs
@xssfox I thought sparkling Smart Cards
-
Passkeys are just sparkling TLS client certs
@xssfox worse, since their cryptographic auth is one-time, exchanged for a long-lived stealable cookie
-
Passkeys are just sparkling TLS client certs
@xssfox shutup shut up SHUT UP SHUT
/lh
-
Passkeys are just sparkling TLS client certs
I love how this annoys or clicks with people in different ways
-
Passkeys are just sparkling TLS client certs
@xssfox at least there's no PKI attached to them (I THINK?????????) -
-
Passkeys are just sparkling TLS client certs
@xssfox : no they're not.
IIRC client certs are bound to the TLS channel, while passkeys are bound to the domain name.
Passkeys do not protect against DNS domain takeovers or BGP hijacks (where a malicious website hijacks the domain name and obtains a valid https website certificate).
OTOH if your browser has a TLS connection to a MitM proxy such as Cloudflare or Fastly, you're dead in the water anyway.
-
@xssfox I thought sparkling Smart Cards
-
-
R relay@relay.infosec.exchange shared this topic