So... turns out hardware signing on browsers means nothing basically - when you use touch ID and such, a private and public keys are generated.
The server gets the public key, the private is generated each time the hardware verifies you and sent to server (hashed i guess), the joint key confirms its you.
but... on chrome/safari that private key can also be generated by code and sent with a command. so a hacker can just create that each time and there's no way for the browser to know if it was created from hardware or not.
so... next up - MOBILE APP SIGNING.
Currently in review.