logoalt Hacker News

lxgryesterday at 2:27 PM0 repliesview on HN

Beyond "just" being phishing resistant, for banking/payments, WebAuthN even has the opportunity of providing "what you see is what you sign":

The Secure Payment Confirmation [1] extension to WebAuthN supports using passkeys on third-party sites (think merchant checkouts) and including signed structured messages (think "confirm payment of <amount> at <merchant> on <today>").

It wouldn't be crazy to imagine authenticators with small OLED displays to provide an end-to-end secure channel for displaying that information, similarly to how cryptocurrency hardware wallets already do it.

Of course, this would require a certain popular hardware and software manufacturer with a competing payment solution to implement the extension...

[1] https://www.w3.org/TR/secure-payment-confirmation/