Conversation

Replying to
* caveat: HSMs providing FIDO/U2F/WebAuthn eliminate phishing, which provides a lot of value, but you don't need an HSM for that, a software-only implementation would work about as well, and i have no idea why isn't that deployed everywhere yet
9
32
Replying to
what i'm saying is that as a browser vendor -and- website maintainer, adopting webauthn makes authentication flow both more secure and less annoying, so these parties should adopt it
1
4
Pairing-based attestation isn't user hostile and has compelling security properties. Chaining to an intermediate or root is broken by an adversary extracting the provisioned batch key from even a single device. At best it's a weak way to bootstrap a more meaningful pairing model.
1
1
Show replies