1. Improve the UI of client certs. 2. Figure out a way to manage credentials across multiple devices.
1. Improve the UI of client certs. 2. Figure out a way to manage credentials across multiple devices.
Google reportedly managed to all but eliminate phishing targeted at employees [1].
They also kind of solve your point 2: since the credentials live on the token, it's easy to move them from one device to the next. For devices with USB/NFC, that is.
[1] https://krebsonsecurity.com/2018/07/google-security-keys-neu...
So I have a cheap FIDO token on my keychain that I take everywhere, and then I have one permanently plugged into the big desktop PC in my home and one in a desk drawer. You can buy ones that work nicely with a phone (unless you have an iPhone, can't help Apple) and Microsoft intends to effectively build one into Windows installs.
If you see a WebAuthn deployment that does 1:1 users to FIDO tokens, those people don't know what they're doing and need re-educating just like when people go "Oh, MD5(password) seems pretty secure".
Neither of these solutions helps with spear phishing emails, either. If you get an email that says "please wire money" from a sender you think you trust, the attacker's goal isn't credential harvesting, so protecting logins won't help.
Similarly we're seeing people fall for scams where a "trusted person" asks them to buy a bunch of iTunes gift cards and provide the codes on them in a reply email. Yes, people actually comply with this request when they think the requester is their CEO, etc.
Maybe I'm happy for Hacker News and GitHub to know me as Nick Lamb, but I'd prefer that Grindr thinks of me as Steve Farmer, so that's now an additional certificate and then some sort of choice mechanic so I pick the right one. And if I screw up, or an advertising network is able to tie these identities together I can't undo that.
WebAuthn create a scenario where you can prove to a site that _you_ still have the same FIDO token as when _you_ signed up. But they don't get anything else, you have to mount an _active attack_ to even find out whether the token Alice shows you when she logs in is really the same token that Bob shows when he logs in, or to find out whether the credentials you've stolen from Facebook for alice@example.com are for the same token that Bob is using on GitHub. Passive attacks can't find any of that out, and remember each active attack attempt causes a physical human interaction, you can't just write a Javascript to try it a billion times until it succeeds.