You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In addition to the use of WebAuthn or a password manager, auto-complete of an SMS code may also be a trustworthy signal of the user logging in and should be included in the browser mediated category.
The text was updated successfully, but these errors were encountered:
At the same time, push notifications to a trusted App are much more secure. While the browser can't detect this (push to app) method directly, it is a better authentication method than SMS codes. I am concerned about the browser treating this method as a "mediated" method which is less secure than other methods which can not be classified as "mediated". It may push sites to use less secure authentication methods which weakens the security of the user.
In addition to the use of WebAuthn or a password manager, auto-complete of an SMS code may also be a trustworthy signal of the user logging in and should be included in the browser mediated category.
The text was updated successfully, but these errors were encountered: