Hacker News new | ask | show | jobs
by poincaredisk 416 days ago
>they are phishing resistant

But can be easily stolen by malware (unless someone adds a client cert OS support? intriguing idea). But so can passkeys stored on the same device, so I don't know.

Long time ago browsers even had a widget to generate client certs natively! But it was removed, probably because of lack of use.

1 comments

All is lost the moment you have malware on your device. It can just steal the session key after authentication.