v145 · Web APIs · Payments · Security · demo

Risk Scenario Comparison

Browser-bound keys add device-level proof to every SPC transaction assertion. Walk through four attack scenarios — phishing, malware, credential stuffing, device theft — and see what an attacker can and cannot do with and without browser-bound keys.

live replay proof

Run the same cross-device replay check against the backend verifier: Device A is enrolled, Device B signs the browser-bound portion, and the relying party rejects the transaction.

No replay proof run yet.

risk matrix

Attack scenario SPC without browser-bound keys SPC with browser-bound keys (Chrome 145+)

see also