4 ms·
>But we're implementing the W3C Web Authentication (webauthn) spec and you can already use it in Chrome in place of U2F. How are users going to differentiate b
by danjoc 8y ago
>But we're implementing the W3C Web Authentication (webauthn) spec and you can already use it in Chrome in place of U2F.
How are users going to differentiate between a webauthn permission request and a webusb permission request? The later can be used for phishing attacks, which appears to defeat the entire purpose of having a U2F key.
https://www.wired.com/story/chrome-yubikey-phishing-webusb/ https://www.wired.com/story/chrome-yubikey-phishing-webusb/
- agl 8y agoWebauthn and WebUSB UIs are very different. Additionally, Chrome has banned WebUSB from claiming Security Keys. However, it remains the case that if the user downloads and runs exes, or otherwise grants the attacker direct access to the Security Key, then they can ask it to sign an authentication request for a given website. Such an attacker could also compromise the browser and wait for the user to login themselves etc.
- danjoc 8y ago>Chrome has banned WebUSB from claiming Security Keys Since when? Is this extension now broken? https://chrome.google.com/webstore/detail/smart-card-connector/khpfeaanjngmcnplbdlpegiifgpfgdco?hl=en https://chrome.google.com/webstore/detail/smart-card-connect...
- agl 8y agoI don't know about the specific extension, but see https://groups.google.com/a/chromium.org/d/msg/blink-dev/LZXocaeCwDw/GLfAffGLAAAJ https://groups.google.com/a/chromium.org/d/msg/blink-dev/LZX...
- wolf550e 8y agoSince webusb broke u2f: https://pwnaccelerator.github.io/2018/webusb-yubico-disclosure.html https://pwnaccelerator.github.io/2018/webusb-yubico-disclosu...