|
|
|
|
|
by pornel
1576 days ago
|
|
"Simpler" is a weasel word that can either mean "easier" or "more primitive", and in this case it's the latter. Webauthn doesn't require separate keys per site and user vigilance to stay secure, because it has a-not-so-simple challenge-response protocol that is site-specific. For end users Webauthn is easier to use: just press a foolproof button. I don't want to sound too negative. ed25519 keys are neat, and have fun implementing software using them. Let's just be realistic that a practical cryptographic system needs many more features, and Webauthn has them for a reason. |
|