Hacker News new | ask | show | jobs
by effisfor 1155 days ago
One possibility for WebAuthn over email/password is the easy retrieval of local, strong and domain-unique encryption key material via the prf extension. Support for this is currently limited to Chrome Canary + hardware key, but MasterKale thinks it will be coming to other browsers, and biometric:

https://blog.millerti.me/2023/01/22/encrypting-data-in-the-b...