3 ms·
Does anybody understand how passkeys protect against phishing more than OTP codes do? With OTP codes, an attacker can just ask the user to share their code ("pl
by sunaurus 4y ago
Does anybody understand how passkeys protect against phishing more than OTP codes do? With OTP codes, an attacker can just ask the user to share their code ("please share your 2fa code to authenticate yourself"), surely with passkeys the same attacker could just ask the user to scan the login QR code ("please scan this QR code to authenticate yourself").
Edit: I looked into it a bit more, it seems like it only works if the browser and scanning phone are in bluetooth range. That's definitely pretty good in terms of phishing protection, but a hard dependency on bluetooth would mean this will not work at all on many desktop computers...
- red_admiral 4y agoFIDO authentication, of which webauthn is the successor, works like this: your secret is a signing key for a digital signature cryptosystem. When you authenticate, it signs a message containing various things including the hostname of the site being authenticated to, and because this is under the control of the browser, a phishing site can't fake it easily (also the browser will throw a fit if you're not on https). The result is that if you are tricked into entering your credentials into google.com.totallynotaphishingsiteipromise.evilsite.com which is doing a man-in-the-middle attack against the real site - maybe with a let's encrypt cert so they can do https on their own domain name - then the authentication token they send to the real google will have the correct signature, but the wrong domain name.
- sunaurus 4y agoI was more worried about attacks where the attacker takes a screenshot of the QR code and sends it to the user while pretending to be a support agent. So the user never even opens any evil site in their browser.
- thealistra 4y agoScanning a qr code triggers a bluetooth bridge to continue. If a scammer or your mom scans it from someplace else, it won’t work. Good for antiphishing. Bad for oops, left phone at home.
- sofixa 4y ago> then the authentication token they send to the real google will have the correct signature, but the wrong domain name. So a domain hijacking attack is the only possibility? (and made drastically harder for serious websites with Certificate pinning)
- red_admiral 4y agoWell, if you can get the user to install malware on their computer ("you must update your flash plugin to continue ...") then you could potentially fiddle with their certificate store, or many other things.
- choko 4y agoThere is not a solid consensus on cert pinning, and for good reason. https://www.digicert.com/blog/certificate-pinning-what-is-certificate-pinning https://www.digicert.com/blog/certificate-pinning-what-is-ce...