|
|
|
|
|
by bedast
1511 days ago
|
|
What this article is about is authenticating the request with an app on your phone, not a hardware key. This ends up being a device totally disconnected from the device requesting the auth, and neither have to be in the same geographic location unless implemented alongside the spec. |
|
For me the question is if this is a webauthn thing in general or a security key thing (to include the domain in the challenge to prevent phishing)