Sample Header Ad - 728x90

Unexpected WebAuthn / passkey prompt

1 vote
0 answers
78 views
Safari prompted me to authenticate to ioc.exchange today, when I had no Safari tabs or windows with ioc.exchange open. I do have an ioc.exchange account that I use only rarely. I do not have ioc.exchange set up in Internet Accounts, and I was in Safari when the popup surfaced. Edit: Someone may be poking around ... I just got an unsolicited push MFA request from Microsoft Authenticator. Probably just a coincidence but wanted to mention it. Edit 2: Not answer but I spoke with someone involved in the development of FIDO2 specs who assured me the dialog box could only pop up if "... something made a call from that origin in an app or browser." What would have made a call from ioc.exchange to my browser is beyond me. Are there any non-sketchy reasons this might happen? As far as I know webauthn/passkeys doesn't support a push authentication model (someone somewhere else trying to log in as me resulting in a prompt on my machine). enter image description here
Asked by drumboots (123 rep)
Aug 6, 2024, 04:28 PM
Last activity: Aug 8, 2024, 10:55 PM