3 ms·
> If you somehow managed to clone the security key, services would notice that your nonces are no longer monotonically increasing and you could at least detect
by gst 8y ago
> If you somehow managed to clone the security key, services would notice that your nonces are no longer monotonically increasing and you could at least detect that it's been cloned.
At least a year ago or so (last time when I checked) most services didn't appear to check the nonce and worked fine when the nonce was reset.
- justincormack 8y agoIf you can reset the nonce without resetting the key you can probably retrieve the key easily if you can read the traffic. The service should not need to check the nonce, and adding that much state is going to be complicated.
- crunchatized 8y agoIt's not that kind of nonce. It's not even called that formally, it's called the 'signature counter.' It's just a part of the plaintext signed with the keypair. There is zero risk of what you're talking about. And how is it complicated to store a single integer per account and perform a comparison if `counter <= previousValue` at each authentication to see if it's not monotonically increasing? They already store that user's public key and key handle, they can store another 4 bytes. In fact, the WebAuthn spec makes verifying this behavior mandatory. [0] [0] https://www.w3.org/TR/webauthn/#signature-counter https://www.w3.org/TR/webauthn/#signature-counter