Home » PoisonSeed outsmarts FIDO keys without touching them

PoisonSeed outsmarts FIDO keys without touching them

by Wikdaily
0 comments
2FA log in


“If a user whose account is protected by a FIDO key enters their username and password into the phishing page, their credentials will be stolen, just as any other user,” Expel researchers in a blog post. “But with a FIDO protecting their account, the attackers are unable to physically interact with the second form of authentication.”

PoisonSeed attackers seem to have cracked this with a new trick. Instead of stealing or cloning a FIDO key, the attackers just convince users to scan a QR code, an exact copy of the QR prompted in a legitimate cross-device sign-in, that completes the malicious login for them.

“This is a fun attack, and one we all need to instrument for,” said Trey Ford, chief information security officer at Bugcrowd. “Yes, this is doable, and what we need to keep in mind is that every security control, on some level, will have failure modes.”

You may also like

Leave a Comment

Welcome to WikDaily, your trusted source for the latest news, trends, and insights across the globe. We are a dynamic blog-style news platform committed to delivering fast, accurate, and engaging content across a variety of topics—from breaking headlines to deep dives into tech, business, entertainment, travel, sports, and more.

Edtior's Picks

Latest Articles