Malware can just steal cookies and ne'er-do-wells can read access tokens from localStorage with XSS.
Edit: Experts, please show how passkeys prevent local cookie theft by infostealer malware and cross-site scripting attacks targeting long-lived auth tokens in localStorage (which isn't subject to HttpOnly/Secure restrictions).
FidoTheDog•4h ago
Malware can just steal cookies and ne'er-do-wells can read access tokens from localStorage with XSS.
Edit: Experts, please show how passkeys prevent local cookie theft by infostealer malware and cross-site scripting attacks targeting long-lived auth tokens in localStorage (which isn't subject to HttpOnly/Secure restrictions).