Michael David Kuckuk

Results 67 comments of Michael David Kuckuk

I'm also encountering a similar issue while working on Signal Desktop (an Electron app). My error message is slightly different: ``` TypeError: Cannot read properties of null (reading 'insertBefore') at...

Seems very possible. I'm not seeing Netflix itself making any calls to the Shakti API either after some brief checks here and there. They've been constantly changing details of their...

Oh, cool! Thanks for the info! Perhaps this could be added to the documentation? I wasn't able to find anything there. I'd suggest something here: https://github.com/jsr-io/jsr/blob/ddcbc46a6c1c9508674cd1cd7b9d9f35d1fc8e0f/frontend/docs/writing-docs.md?plain=1#L174-L176 Let me know if...

Wow, I'm 5 hours late to ask this exact question! 🤯 However, I'd like to add that it would be nice to add integrity protection not only for `PublicKeyCredential.authenticatorAttachment`, but...

> ... the adverse effects it is likely to have in the greater ecosystem (consumer, unmanaged context) Could you perhaps elaborate on this a bit? What issues would arise from...

@timcappalli > Physical proximity attacks are largely outside the threat model. Makes sense. If that means that WebAuthn won't consider any changes aimed at preventing such attacks, the rest of...

> Either way, I don't think that just adding a detection mechanism is the right way to go. The proper solution should be to either eliminate the vulnerability from the...