Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How come? Last I checked there was a devtool to create virtual authenticators. Unless there’s a way for wikipedia to permit only certain vendors like Yubico, akin to browsers trusting certain CAs, I don’t see how one couldn’t make a bot register thousands of accounts with virtual authenticators.


Yes, assertion for manufacturing source is part of WebAuthn.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: