I’ve tried adding YubiKey as a Passkey to an Internet Identity to test several things…
It’s working okay but to my HUGE surprise it doesn’t ask for a pin - which is horrible for security, what happenes if someone steals it or I just lose it.
Does it mean someone can just go and brute force all Internet Identity numbers(it’s not so hard, they are all sequential and correlated with II creation date) and use this YubiKey like nothing happened?..
Seems like a GLARING security hole