FB pixel

Strategies to secure passkeys against authentication vulnerability proposed

Strategies to secure passkeys against authentication vulnerability proposed
 

A recent blog post from eSentire discussed new strategies to secure passkeys and prevent authentication method redaction attacks, a technique used by cybercriminals to bypass security measures. These attacks involve manipulating the authentication process.

Authentication method redaction attacks involve bypassing primary authentication methods in favor of less-secure backup methods, which in turn enables Adversary-in-the-Middle (AitM) phishing attacks. eSentire demonstrates such an attack against Github, but says that numerous passkey implementations are similarly flawed.

The cybersecurity threat detection provider suggests that implementing multiple passkeys is a way to mitigate the threat of AitM attacks, so that losing one passkey neither blocks the user’s access nor requires a fallback to a less-secure authentication method. Magic links can also help, as a relatively secure fallback authentication method, but eSentire also introduces the concept of “warded links.”

Warded links are magic links that provide “a new secure authentication flow, isolated from any existing AitM-compromised session,” the post explains.

The company also recommends red-teaming authentication flow designs, ensuring that any move away from passkeys also initiates a new session, and using behavior analytics and a managed detection and response service to continuous protection and fast threat mitigation.

Analysts have identified potential man-in-the-middle (MITM) attacks targeting session cookies, which can be stolen post-authentication to impersonate users.

Despite the vulnerabilities, however, passkey adoption is growing rapidly.

Recently, Australia’s myGov app integrated passkeys, in a bid to provide a more secure authentication method for users. Mastercard announced its commitment to implementing passkeys and full tokenization for payments in the EU by 2030, and AWS added support for passkeys in June.

Related Posts

Article Topics

 |   |   | 

Latest Biometrics News

 

IDScan confirms breach after 170M identity documents put up for sale

New Orleans-based ID verification provider IDScan.net has acknowledged the major breach of one of its databases, that exposed more than…

 

Microsoft launches Age API, following OS-level declared age range model

Whether because of its age, its product focus or its relatively anemic branding, Microsoft has not caught much public scrutiny…

 

IEEE developing parental consent standard for online age assurance

Talking about age assurance means talking about parental consent. Many continue to maintain that parents are the best arbiters of…

 

Touch Biometrix’ TFT technology reaches market with Lakota FAP60 scanner

The new FAP60 fingerprint biometric scanner from Lakota Software Solutions works natively with iPhones and iPads, which the company says…

 

Advance.AI targets regional growth as SE Asia’s local IAD provider

Singapore-headquartered digital identity verification, compliance and credit information provider Advance.AI is positioning itself as the native regional choice for biometric…

 

Myanmar’s digital ID strategy comes amid a fraught landscape

Myanmar’s military government is accelerating construction of national digital identity infrastructure despite ongoing civil war, using a phased deployment strategy…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events