You are viewing a single comment's thread from:

RE: A Step-by-step Tutorial to REMME Passwordless WebAuth Demo

in #security6 years ago (edited)

If someone gain access to the browser with the imported cert, he/she will be able to authenticate to all the connected sites. But that holds true for all websites (e.g. Facebook and Twitter) which allow users to keep a logged in session on their browsers.

The risk comes when somehow someone got hold of your certificate (with the private key). But even with that, your key should be still stored in encrypted format and require a password in order to be imported to a browser.

On top of that, REMME also supports 2FA, so your Google Authenticator/Authy will also need to be compromised in order for others to gain full access.

Sort:  

Thanks, I shall check that out

Coin Marketplace

STEEM 0.17
TRX 0.16
JST 0.029
BTC 60936.63
ETH 2387.63
USDT 1.00
SBD 2.61