(no title)
mwwaters | 3 years ago
A public/private key alone would have a similar issue, but the browser for FIDO keys gives the domain it's actually talking to. The domain is authenticated with TLS or the browser on an uncompromised machine won't send that domain over. The device only signs the challenge with the private key generated for that specific domain.
oceanplexian|3 years ago
mwwaters|3 years ago
Anyway, the user would likely still click the link in the email since they are trying to log in.