Post details
In today's lesson titled "don't roll your own auth". I just realized the "protected" part of my personal web app was just validating that the Yubikey OTP was a valid OTP not that it was a valid OTP for MY Yubikey.
Richard H. Boyd (@rchrdbyd)Sat, 26 Mar 2022 16:30 GMT