Spyke

Posts

cybersecurity·CybersecuritybyCanard

Webauthn Attestation and OpenSource Keys

Webauthn (Passkeys) are only going to become more important in the future and as this grows, deployments with higher security risks and criticality are going to need to start to understand and embrace attestation of their keys.

In their current form, almost all software products and IDM's today allow you to enroll any cryptographic authenticator. It doesn't matter what make or model it is, it will be allowed.

However, not all authenticators are made equal. They each have different properties, security features, and some even have security issues affecting their hardware or software. Because webauthn is a self contained multiple factor authenticator, this means we need to be even more careful to ensure these devices are secure.

https://fy.blackhats.net.au/blog/2023-12-02-attestation-and-opensource/Open linkView original on fedia.io
2
cybersecurity·CybersecuritybyCanard

What the !#@% is a Passkey?

A new login technique is becoming available in 2023: the passkey. The passkey promises to solve phishing and prevent password reuse. But lots of smart and security-oriented folks are confused about what exactly a passkey is. There’s a good reason for that. A passkey is in some sense one of two (or three) different things, depending on how it’s stored.

What the !#@% is a Passkey?https://www.eff.org/deeplinks/2023/10/what-passkeyOpen linkView original on fedia.io
5

You reached the end