Hacker News new | ask | show | jobs
by tadfisher 605 days ago
Your passkey provider will simply refuse to show that it has a credential for Bob's phishing convincing phishing site. RP challenges are bound to a domain for this purpose.