Hacker News new | past | comments | ask | show | jobs | submit login

https://datatracker.ietf.org/doc/draft-kasselman-cross-devic... explains this attack vector in great detail and suggests some mitigationz.

Their most interesting suggestion is to use the Hybrid transport of CTAP2.2 (not published yet) to perform cross device authorization in a secure way.

This involved proving proximity over Bluetooth Low Energy and a key exchange. Then the Webauthn flow happens over an encrypted channel through a TURN server.

Problem is that your cli tool now needs access to BLE. We're not there yet.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: