FB pixel

Strategies to secure passkeys against authentication vulnerability proposed

Strategies to secure passkeys against authentication vulnerability proposed
 

A recent blog post from eSentire discussed new strategies to secure passkeys and prevent authentication method redaction attacks, a technique used by cybercriminals to bypass security measures. These attacks involve manipulating the authentication process.

Authentication method redaction attacks involve bypassing primary authentication methods in favor of less-secure backup methods, which in turn enables Adversary-in-the-Middle (AitM) phishing attacks. eSentire demonstrates such an attack against Github, but says that numerous passkey implementations are similarly flawed.

The cybersecurity threat detection provider suggests that implementing multiple passkeys is a way to mitigate the threat of AitM attacks, so that losing one passkey neither blocks the user’s access nor requires a fallback to a less-secure authentication method. Magic links can also help, as a relatively secure fallback authentication method, but eSentire also introduces the concept of “warded links.”

Warded links are magic links that provide “a new secure authentication flow, isolated from any existing AitM-compromised session,” the post explains.

The company also recommends red-teaming authentication flow designs, ensuring that any move away from passkeys also initiates a new session, and using behavior analytics and a managed detection and response service to continuous protection and fast threat mitigation.

Analysts have identified potential man-in-the-middle (MITM) attacks targeting session cookies, which can be stolen post-authentication to impersonate users.

Despite the vulnerabilities, however, passkey adoption is growing rapidly.

Recently, Australia’s myGov app integrated passkeys, in a bid to provide a more secure authentication method for users. Mastercard announced its commitment to implementing passkeys and full tokenization for payments in the EU by 2030, and AWS added support for passkeys in June.

Related Posts

Article Topics

 |   |   | 

Latest Biometrics News

 

Biometrics providers and systems evolve or get left behind

Biometrics are allowing people to prove who they are, speeding journeys through airports, and enabling anonymous online proof of age,…

 

Findynet funding development of six digital wallet solutions

Finnish public-private cooperative Findynet has announced it will award 60,000 euros (US$69,200) to six digital wallet vendors to help translate…

 

Patchwork of age check, online safety legislation grows across US

As the U.S. waits for the Supreme Court’s opinion on the Texas case of Paxton v. Free Speech Coalition, which…

 

AVPA laud findings from age assurance tech trial

The Age Verification Providers Association (AVPA), and several of its members, have welcomed the publication of preliminary findings from the…

 

Sri Lanka to launch govt API policies and guidelines

Sri Lanka’s government, in the wake of its digital economy drive, is gearing up to release application programming interface (API)…

 

Netherlands’ asylum seeker ID cards from Idemia use vertical ICAO format

The Netherlands will introduce new identity documents for asylum seekers Idemia Smart Identity, compliant with the ICAO specification for vertical…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events