WebAuthn Signature Counters Are Clone Signals, Not Identity Proofs
WebAuthn Signature Counters Are Clone Signals, Not Identity Proofs A relying party can verify a valid WebAuthn assertion and still receive a counter value that adds no useful evidence about credential cloning. The signature proves possession of the credential private key for the signed assertion. The signCount field has a narrower role: when an authenticator maintains a usable signature counter, changes in that value can give the relying party evidence that the same credential may be active in more than one place.