Someone explain dpop in the browser to me. If the keys are long-lived then I just steal them at the same time as the token? What's this actually protecting against? Someone compromising a corp middleware box? Cloudflare being popped?
Someone explain dpop in the browser to me. If the keys are long-lived then I just steal them at the same time as the token? What's this actually protecting against? Someone compromising a corp middleware box? Cloudflare being popped?
If you have a fediverse account, you can quote this note from your own instance. Search https://nondeterministic.computer/users/mjg59/statuses/114427870405783300 on your instance and quote it. (Note that quoting is not supported in Mastodon.)