4 ms·
You can include the transaction ID in the clientDataHash calculation, which will be signed by the authenticator. This protects against that attack. https://fid
by grnmamba 4y ago
You can include the transaction ID in the clientDataHash calculation, which will be signed by the authenticator. This protects against that attack.
https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-20210615.html#authenticatorGetAssertion https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-cl...