You can add biometric authentication to your webpage. Here’s how
stackoverflow.blog
stackoverflow.blog
Ummm, "MUST"? (emphasis is mine).
Too bad that we cannot somehow make this requirement word a "SHALL" as this leg of the "ceremony" can easily be overridden by a malicious JavaScript function(s).
Unless these JavaScript scripts AND its references HTML pages are also:
- under the protection of nonce hash values,
- complex CSP properly scoped,
- older WebAuthn protocol made client-side rejectable,
- its server-supplied JavaScript logic gets pre-tested in its client browsers prior to the ceremony,
- CTAP1 properly rejected, AND
- the browser is also deemed provably secured from an nonce override.
Awful lot of conditions such that it reminds me of the children's game of "Jenga" (a tower of stacked rectangular blocks) ... reaching for the sky.
Surely, our large pool of esteemed and well-trained web ninjas can handle this seemingly "nuclear-safety" checklist with relative ease. /s
More must be done to streamline this before web integrity gets properly and safely restored in these days and ages.