📢 Moderators Needed 🚀

Moderators are needed with resources to post or have access to resources to post. Submit an application to be considered.
K

RSS Adding, editing or removing passkey does not require user re-authentication

  • Thread starter Thread starter Kirby
  • Start date Start date
K

Kirby

Guest
Guest or Bot
Adding, editing or removing a passkey does not require password confirmation.

This allows kinda easy "account lockouts" by unauthorized actors if they are able to access an active session.

Suggested Fix
Adding, editing or removing a passkey should require re-authentication of the user (password if no 2FA is available, Password + 2FA if no Passkey is available or also Passkey without password if at least one Passkey is available)

Continue reading...
 
Similar content Most view View more
Back
Top