Adversary-in-the-middle attacks can strip out the passkey option from login pages that users see, leaving targets with only authentication choices that force them to give up credentials.

  • CaptObvious@literature.cafe
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    10
    ·
    edit-2
    13 days ago

    Wait, haven’t some sources been touting how ultra-secure and unbreakable passkeys are? And now we find that they’re susceptible to comparatively simple MITM attacks?

    • Reddfugee42@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      2
      ·
      13 days ago

      Passkeys are so secure that it’s easier just to hack the page and not offer them as a login option, but that’s your takeaway and you got multiple upvotes? God help us.