| ▲ | zdp7 2 days ago | |||||||
There is security value. A passkey will not work anywhere except the actual website. Fake look a like sites can't get the credentials. Evidently they can trick you into authorizing their device. | ||||||||
| ▲ | harshreality 2 days ago | parent | next [-] | |||||||
That's also how any good password manager works. You'd have to manually copy-paste the password to get around the same-site fill restriction (whether it's autofill or manual fill). | ||||||||
| ||||||||
| ▲ | thyristan 2 days ago | parent | prev [-] | |||||||
Sure? MitM isn't a new kind of attack, and I'd be surprised if the ball-of-wax-and-javascript that is WebAuthn isn't vulnerable to that... | ||||||||
| ||||||||