You are here |
golb.hplar.ch | ||
| | | |
www.stackallocated.com
|
|
| | | | The process (and pitfalls) of upgrading a U2F-supporting website to WebAuthn, with demonstration code. | |
| | | |
janko.io
|
|
| | | | Passkeys are a modern alternative to passwords, where the user's device performs the authentication, usually requiring some form of user verification (biometric identification, PIN). Passkeys are built on top of WebAuthn specification, which is based on public-key cryptography. Keypairs are created for each website, and the public key is sent to the server, while the private key is securely stored on the device. This makes passkeys: | |
| | | |
blog.trailofbits.com
|
|
| | | | This post will examine the cryptography behind passkeys, the guarantees they do or do not give, and interesting cryptographic things you can do with them, such as generating cryptographic keys and storing certificates. | |
| | | |
tilde.town
|
|
| |