A security architect rates an authenticator that stores keys in a Trusted Execution Environment (TEE) versus one using software-only storage. What risk difference is most significant?
-
A
TEE authenticators are slower and increase latency risk
-
B
Software-only key storage is more vulnerable to OS-level malware extracting the private key
-
C
TEE authenticators cannot support user verification
-
D
Software authenticators provide stronger attestation certificates