3 ms·
This is a mildly interesting observation/tool presented in the most overblown and irresponsible way. WebAuthN is meaningfully phishing-safe. You can’t replay a
by FiloSottile 4y ago
This is a mildly interesting observation/tool presented in the most overblown and irresponsible way.
WebAuthN is meaningfully phishing-safe. You can’t replay a login for attacker.com to example.com. What part 1 is demonstrating is that if you compromised the victim’s machine you can arbitrarily use a token for as long as it’s connected. What part 2 is demonstrating is that if you choose server-side to allow subdomains (it’s an option!) and then an attacker takes control of https://subdomain.example.com https://subdomain.example.com, they can replay a subdomain login against example.com.
Needless to say, your average phisher doesn’t have control over the victim’s machine or one of the target’s subdomains. It’s still interesting because you might encounter a combination of server-side misconfiguration and user controlled subdomains (like the deprecated user.github.com), but far from an indictment of WebAuthN.
Arguing that calling WebAuthN phishing-safe is a “scam” or that 100% phishable TOTP or MFA over Signal (??) is better is detached from reality and harmful. I wish InfoSec didn’t reward these antics.