Join Nostr
2025-07-24 15:53:21 UTC
in reply to

Dan Goodin on Nostr: The company that reported (incorrectly) finding a way to bypass FIDO2-based MFA says ...

The company that reported (incorrectly) finding a way to bypass FIDO2-based MFA says it's "collaborating with the FIDO Alliance to review the attack." It goes on to say: "We are working together to review our findings and will publish a follow-up as soon as possible." So far no one outside the company (and possibly inside) has been able to reproduce the attack.

FIDO2 is the world's greatest hope yet in battling credential phishing. It's such a shame that this research got published before the findings could be confirmed.