Breaking WebAuthn, FIDO2, and Forging Passkeys

17 vmfunc 1 6/20/2025, 4:55:39 PM nullpt.rs ↗

Comments (1)

rlpb · 5m ago
I'm not sure what this "breaks". Unless a site requires attestation and validates that attestation, a bad software FIDO2 implementation will leave users vulnerable should they choose to use one.

Didn't we already know this?