|
|
|
|
|
by blibble
560 days ago
|
|
there is attestation of the registration device in webauthn so you can tell that a token was signed by an official yubikey, apple secure enclave, tpm, etc for yubikeys the attestation signing certificate is shared between devices, but this number is limited so you could rate limit... just it would be a horrible experience when you are limited |
|