Passkeys, Permissions Policy and Bug Hunting in 1Password's WebAuthn Wrapper (opens in new tab)
Passkeys are the best thing to happen to web authentication in years, but a passkey ceremony is only as secure as the stack enforcing it. The browser, the relying party, the authenticator, and any extension sitting between them all need to honour the same rules. While investigating WebAuthn behaviour, I
Read the original article