Earlier quoted context omitted.
So Google and Amazon have support, and it seems depening on which AB group you are in Apple does too? I think it is a significant benefit and likely to be implemented specially concidering client support is already there and there are good libraries available to do it.
Large providers have supported other standards and not seen uptake. I'll believe it if/when it happens. Lack of understandably is the primary downside of passkeys, and I doubt it will be overcome in this decade. Authentication is like investing, one must understand the options for it to be effective.
A clickjacking vulnerability in WhatsApp that enables phishing attacks
81–84 of 84 posts
There’s plenty of inertia but if you haven’t tried it, the experience on Apple devices is pretty easy to understand and fast: “Do you want to sign in with Face ID for the web?” takes less time than weakening your password to suit some site’s policy, and it’s much faster and easier than dealing with any other form of MFA. At least for sites required to have MFA, that inertia is going to win out faster than we think because ordinary people hate things like TOTP codes and stuff like SMS/email codes will trigger accessibility complaints.
Re: A clickjacking vulnerability in WhatsApp that enables phishing attacks
#82Re: A clickjacking vulnerability in WhatsApp that enables phishing attacks
#83This is a pretty clever combination of feature misuse, although I think I'd rate the overall security impact fairly low, because the best-case scenario is that you cause the recipient to open a link in their browser. That can be useful in some cases, but unless the attacker is a police force, intelligence agency, or similar, there would usually need to be some kind of follow-up attack, e.g. exploiting unpatched softw…
If that link shows a login screen identical to the Instagram one, what percentage of users do you think will double-check the URL a second time, after mistakenly confirming it in the WhatsApp preview?
Re: A clickjacking vulnerability in WhatsApp that enables phishing attacks
#84What’s happening with the Whatsapp osx app. It’s so bad to use nowadays, slow, buggy.
It's an Electron app, they also have a native one in beta you can download
The native mac os app is worse imo. On the other hand the windows app is one of the best windows messaging apps I've used. They need to re think their strategy on macos.