|
|
|
|
|
by RaisingSpear
808 days ago
|
|
> That's why I qualified it with "certificate-based". The private key never leaves the device Except that phishing doesn't require the private key - it just needs to echo back the generated token. And even if that isn't possible, what stops it obtaining the session token that's sent back? |
|