Hacker News new | ask | show | jobs
by not_that_noob 2962 days ago
Not finding fault. The point of Webauthn is convenience - but the trade off is that if CTAP is compromised, it’s convenient for the attacker too.
1 comments

I don't see how that's different from passwords, though. If your password gets compromised, it's game over as well, and it's much easier to compromise that.