FB pixel

FIDO gets an apology and endorsement for spider infestation prevention reiterated

Passkeys cleared of alleged MFA bypass phishing vulnerability
FIDO gets an apology and endorsement for spider infestation prevention reiterated
 

A pair of cybersecurity updates represent not just wins for the FIDO protocol, but also a possible swan song for a certain, legacy version of multi-factor authentication. A reported passkey vulnerability has been walked back, and FIDO is recommended as the fix to the vulnerability of “phishable” MFA wreaking havoc on corporate networks around the world.

The PoisonSeed attack reported by security company Expel earlier this month does not give access to protected assets, if the FIDO Cross-Device Authentication flow is properly implemented.

The alleged vulnerability involved using the “cross-device sign-in” feature of FIDO passkeys and social engineering to execute an adversary-in-the-middle (AitM) attack. The attack was able to successfully pass the password factor of the authentication flow by getting a the target, likely an employee, to scan a QR code substituted by the attacker for one from Okta, “but all subsequent MFA challenges failed and the attacker is never granted access to the requested resource,” according to a new blog post from Expel.

The explanation comes with an apology, and credit from the Expel team to the FIDO community for its engagement.

FIDO keeps Spiders out

Legacy MFA methods were blamed for a recent spate of successful hacks by the Scattered Spider attack group exposing data from major airlines.

An advisory from the U.S. Cybersecurity & Infrastructure Security Agency has been updated to note tactical changes retains a recommendation to “(i)mplement FIDO/WebAuthn authentication or Public Key Infrastructure (PKI)-based MFA.”

“These MFA implementations are resistant to phishing and not suspectable to push bombing or SIM swap attacks, which are techniques known to be used by Scattered Spider actors,” the alert states.

Later, the advisory tells organizations to “(r)equire phishing-resistant multifactor authentication (MFA).”

CISA partnered with the FBI, Canadian Centre for Cyber Security, Royal Canadian Mounted Police, the Australian Cyber Security Centre’s Australian Signals Directorate, and the Australian Federal Police and National Cyber Security Centre on the advisory.

Other advice includes limiting the use of remote desktop services, implementing a recovery plan, and compliance with NIST password management policies.

The updated advisory adds a caution that the remote access tools hackers use in the attacks will vary, and a recommendation to “enhance monitoring against unauthorized account misuse.”

The global banking industry has also been working on adapting FIDO2 standards so that they can be adopted for financial use cases.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

For ChatGPT, OpenAI rolls out age inference system similar to YouTube’s

One of the more unheralded battles being decided in the development of the age assurance industry is how, exactly, to…

 

Face biometrics image quality assessment tool maturing as eu-LISA plans integration

The Open Source Face Image Quality software library is intended to support large-scale biometrics programs with information about the usefulness…

 

Deepfake voice fraud dupes Swiss businessman into transferring millions

CEO fraud enabled by voice deepfake technology has claimed another victim, this time in Switzerland. Deploying audio manipulated to sound…

 

Deepfake-as-a-Service revolutionizing biometrics spoofing and identity fraud: report

The rise of AI has allowed cybercriminals to access deepfake images, synthetic identities, cloned voices and even biometric datasets for…

 

Regula launches mobile driver’s license reader for verification at scale

Regula has launched a new feature for its document reader software, which will allow organizations to verify mobile driver’s licenses…

 

FBI seeks industry input on classified identity-based biometric system

The Federal Bureau of Investigation (FBI) has issued a Request for Information (RFI) seeking industry input on a new classified,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events