2025-11-12 21:47 UTC
@jerry@infosec.exchange Yeah passkeys are really prone to this as they bake in the domain name now so youre locked in. Not surprised they made a schmozzle out of it.
Replies (1)
-
@endareth@disobey.net 2025-11-13 02:55
@firstyear@infosec.exchange @jerry@infosec.exchange If they implemented passkeys correctly, they could have avoided all this. https://web.dev/articles/webauthn-related-origin-requests shows how passkeys can support multiple related origins.