Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is what Intune and similar provide, but you need some existing, secure registry of devices before this works.

Cross device webauthn is the better solution here but it's still vulnerable to the oauth phishing called out here.



WebAuthn uses such a directory already. Most implementations validate the attestation against a public database of ‘trusted’ device types (and DAA enables this to be done without compromising anonymity, up to the uniqueness of a device type)


That's not a trust statement, and it's not reliable as a proof. You can reliably tell you've seen this authenticator before, but that doesn't solve the problem being described here


Trust is a ladder, and identifying the make/model of device is but one rung of it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: