|
|
|
|
|
by j_san
1503 days ago
|
|
Depending on how it's implemented it could still use the same mechanism, couldn't it? (genuine question) For me the question is if this is a webauthn thing in general or a security key thing (to include the domain in the challenge to prevent phishing) |
|
But, of course, if this is optional, I still have to reference the end users. I'm willing to pay for an authentic FIDO key, which can be a tad costly. Your typical user might be more inclined to go for a cheap one that does enough to get into the account, and may not be trustworthy, or would prefer not to do it at all.