(no title)
tadfisher | 5 days ago
The spoofed app can't request passkeys for the legit app because the legit app's domain is associated with the legit app's signing key fingerprint via .well-known/assetlinks.json, and the CredentialManager service checks that association.
mwwaters|5 days ago
tadfisher|5 days ago
No need for locking down the app ecosystem, no need to verify developers. Just don't use phishable credentials and you are not vulnerable to malware trying to phish credentials.
0: https://www.bankofamerica.com/.well-known/assetlinks.json
unknown|5 days ago
[deleted]