Credential Enumeration
Measure timing differences to detect credential presence and probe conditional mediation behavior.
Step 1: Register a Test Passkey
You need a registered credential to compare timing against fake credentials.
Step 2: Timing Oracle Test
This test will send multiple authentication requests with real, fake, and empty credential IDs. Timing differences may reveal whether a credential exists on this device.
Note: You will need to interact with (or cancel) each authentication prompt that appears. The test runs sequentially -- complete or cancel each prompt to proceed.
Conditional Mediation Check
Check whether the browser supports conditional mediation (autofill-assisted passkey selection).