This is how I assumed it worked as well.
I wasn't aware of the non User Verification method.
I thought the passkey was tied to hardware.
I thought that was the entire point.
How wrong I was it seems.
26 karma · joined July 2, 2019
After how many years of "shifting left" and understanding the importance of having security involved in the dev and planning process, now the recommendation is to vibe code with human intuition, review then spend a million tokens to "harden"?
I understand that isn't the point of the article and the article does make sense in its other parts. But that last paragraph leaves me scratching my head wondering if the author understands infosec at all?
I think its cool, I've been brainstorming how a good MCI would work for a while and didn't think of this. I think its a great novel approach that will probably be expanded on soon.