← Back to context

Comment by jeroenhd

6 hours ago

CTAP2 requires Bluetooth but I'm not seeing any mention of that protocol here? It wouldn't really solve the "are you a human" thing, because you can just implement your own CTAP2 protocol handler if you wanted to write a bot.

I think the phone will just do basic remote attestation and then do a POST request to Google. Still not exactly difficult to bypass for anyone with a dollar to throw at the click/ad fraud farms, though.