|
|
|
|
|
by uzyn
380 days ago
|
|
If C uses it without the knowledge of the original owner (A or B). With proper signCount check, C would have to increment it at its end; A or B would not have known. When A logs in with an unincremented signCount. A and the relying party are now aware of a potential cloned authenticator and disable the compromised passkey. |
|
It seems strictly worse than just sending an email saying "your passkey was used from <IP-based geolocation>, wasn't it you?".