FB pixel

FIDO gets an apology and endorsement for spider infestation prevention reiterated

Passkeys cleared of alleged MFA bypass phishing vulnerability
FIDO gets an apology and endorsement for spider infestation prevention reiterated
 

A pair of cybersecurity updates represent not just wins for the FIDO protocol, but also a possible swan song for a certain, legacy version of multi-factor authentication. A reported passkey vulnerability has been walked back, and FIDO is recommended as the fix to the vulnerability of “phishable” MFA wreaking havoc on corporate networks around the world.

The PoisonSeed attack reported by security company Expel earlier this month does not give access to protected assets, if the FIDO Cross-Device Authentication flow is properly implemented.

The alleged vulnerability involved using the “cross-device sign-in” feature of FIDO passkeys and social engineering to execute an adversary-in-the-middle (AitM) attack. The attack was able to successfully pass the password factor of the authentication flow by getting a the target, likely an employee, to scan a QR code substituted by the attacker for one from Okta, “but all subsequent MFA challenges failed and the attacker is never granted access to the requested resource,” according to a new blog post from Expel.

The explanation comes with an apology, and credit from the Expel team to the FIDO community for its engagement.

FIDO keeps Spiders out

Legacy MFA methods were blamed for a recent spate of successful hacks by the Scattered Spider attack group exposing data from major airlines.

An advisory from the U.S. Cybersecurity & Infrastructure Security Agency has been updated to note tactical changes retains a recommendation to “(i)mplement FIDO/WebAuthn authentication or Public Key Infrastructure (PKI)-based MFA.”

“These MFA implementations are resistant to phishing and not suspectable to push bombing or SIM swap attacks, which are techniques known to be used by Scattered Spider actors,” the alert states.

Later, the advisory tells organizations to “(r)equire phishing-resistant multifactor authentication (MFA).”

CISA partnered with the FBI, Canadian Centre for Cyber Security, Royal Canadian Mounted Police, the Australian Cyber Security Centre’s Australian Signals Directorate, and the Australian Federal Police and National Cyber Security Centre on the advisory.

Other advice includes limiting the use of remote desktop services, implementing a recovery plan, and compliance with NIST password management policies.

The updated advisory adds a caution that the remote access tools hackers use in the attacks will vary, and a recommendation to “enhance monitoring against unauthorized account misuse.”

The global banking industry has also been working on adapting FIDO2 standards so that they can be adopted for financial use cases.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Biometric age assurance market gears up for rapid expansion as rules clarify

Biometric age assurance was turned up to 11 this week, as in 11 different Biometric Update articles on efforts to…

 

Age assurance explained: The laws reshaping the internet

A year ago, age assurance was a niche topic and the biometrics industry was still anticipating the effect that the…

 

EUDI What? As wallet deadline looms, awareness remains low

New consumer research from IDnow shows that only about half of French and German customers have heard of the European…

 

The surveillance networks cities do not have to buy

Private camera networks are beginning to emerge in cities across the U.S. which operate outside the boundaries of companies who…

 

German lawmakers approve live facial recognition use by federal police

Germany’s Federal Police appear on track to get new powers in a broad update of their governing rules, including a…

 

Kantara updates digital identity certification criteria for latest NIST revision

The Kantara Initiative has expanded its certification program for NIST’s Digital Identity Guidelines by releasing new criteria for their latest…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events