Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feature idea: test password manager security and conformance #143

Open
smessmer opened this issue Oct 15, 2024 · 0 comments
Open

feature idea: test password manager security and conformance #143

smessmer opened this issue Oct 15, 2024 · 0 comments

Comments

@smessmer
Copy link

I saw some claims online that a password manager I was considering to use doesn't correctly enforce the RPID domain check and therefore would allow phishing attacks. Not mentioning the password manager in question because I haven't confirmed the rumor.

But wouldn't it be nice if we had a way of testing this? e.g. have webauthn.io use a passkey for a different rpid and see if the password manager accepts it?

And extending on the concept, maybe we could add other checks testing for conformance with other parts of the standard?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant