Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Webauthn is significantly more complicated and conceptually structured around the use of authenticators. DBSC is a rather simple challenge-response scheme that can be bolted on to things that already exist in order to mitigate bearer token exfiltration. Even though they both use public keys the two things solve (slightly) different problems.

Importantly, the presence of attestation in webauthn could potentially compromise privacy or user choice in certain cases. DBSC has zero support for that.

You could certainly use a webauthn credential to establish a DBSC session though.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: