Slide 39
Slide 39 text
What does the authenticator do?
• Verifies identity
Possession, e.g. touch
PIN or biometric
• Stores a new credential
Scoped to the website and user
Phishing resistant – “un-phishable”
• Generates an asymmetric key pair
Stores private key securely
Sends public key to browser
@benjaminlowry #webauthn