How do hackers get around passwordless authentication?

I’m a complete noob going through PortSwigger’s web app academy and was just thinking about this scenario. I want to try and learn as much as I can before a real job interview.

If you were hired to pentest a company that uses passwordless authentication with a physical device like a yubikey, what would you probe first?

submitted by /u/Available_Dream_9764
[link] [comments]

from hacking: security in practice https://ift.tt/JG3KXjd

Comments