Hacker News new | past | comments | ask | show | jobs | submit login

Google actually has this implemented for signing into Google with desktop Chrome and Android, but I'm not sure it's standardized yet. Ideally Google will make this mechanism usable with all WebAuthn-supporting sites.

(It seems like there's two different forms of this that Google has implemented. One form is done simply: when you log into Google, Google tells your phone to show a prompt, but this form is still phishable, because if you're using a phishing site while an attacker is proxying your login, they could still trigger it. The other form involves desktop Chrome talking over Bluetooth to your phone to verify what domain you're looking at. This method is immune to phishing domains like other WebAuthn authentication methods so presumably this is what they'd try to standardize. It does involve multiple moving parts so it's not too surprising it's not standardized yet.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: