joestewart
2024-06-28

In this article I describe a potential attack against many Webauthn (i.e. passkeys or hardware security keys) implementations, that I'm calling an Authentication Method Redaction (AMR) attack.

esentire.com/blog/securing-pas

#passkeys #webauthn #authentication #evilginx #phishing #mfa

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst