The Web Authentication Arms Race – A Tale of Two Security Experts
blog.slaks.net
blog.slaks.net
I would think that anyone with that level of access to compromise the channel would likely be able to just compromise the server itself?
That point is often brought up when discussing security, though personally I think non-maximally-effective attacks are also worth discussing - an attacker may have a reason to refrain from using full powers available for him. For instance, compromising the server immediately may lead to detection and subsequent mitigation of the attack, whereas just tapping a channel may remain undetected for long and let the attacker gather intelligence, select a particular target or perform some other, unexpected attack.
[1] https://www.google.com/search?q=nsa+smiley&es_sm=122&tbm=isc...
Woah there, I don't think this is a realistic expectation of an attacker.
However, the author is right in that it is much easier to attack the endpoints. Users install every piece of software on the planet, and the Firefox/Chrome user storage directory is in clear access for all programs. There are also many remote code execution vulnerabilities in the wild that could be used to query a database server or steal keys.