• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

Experts Raise Interoperability Concerns About FIDO2

June 3, 2022

Experts are warning about potential security and usability concerns with the FIDO2 protocols. The warning comes in the wake of a new paper in the Cryptology ePrint Archive of the International Association for Cryptologic Research that suggests that FIDO2’s Client-to-Authenticator Protocol (CTAP2) may be vulnerable to man-in-the-middle-attacks, and a separate report that suggests that a lack of interoperability could make it difficult to carry credentials across platforms.

Experts Raise Interoperability Concerns About FIDO2

With regards to the former, the writers of the ‘Provable Security Analysis of FIDO2’ paper found that CTAP2 was performing an unauthenticated key exchange, and that the platform’s “pinToken” generation system would sometimes reuse the same credential for multiple interactions. The researchers recommended the use of more secure (and authenticated) binding practices to help close that security gap.

The other problem has more to do with how FIDO technology gets deployed, and the fact that tech giants like Apple, Google, and Microsoft all have their own authentication ecosystems. All three are members of the FIDO Alliance, and all three are taking steps to eliminate passwords.

In practice, that means that the companies are using device biometrics for identity verification, and then using that initial authentication event to speed up logins in apps and web browsers. The feature is comparable to a password manager, insofar as the device remembers the user and removes certain barriers while that person is at the helm. The big tech giants can also carry some of that utility across multiple devices through the cloud. For example, Apple could remember the facial biometrics of someone with an iPhone, and use that to streamline that person’s experience when they try to log into a Mac computer.

That latter feature is ultimately at the root of the problem. As long as a user stays on one ecosystem, it is relatively easy to transfer someone’s authentication passkeys. However, that is not the case if someone wants to switch from an iPhone to an Android device (for example). The current FIDO2 system allows people to swap credentials one application and account at a time, but does not have a mechanism for a secure and large-scale batch exchange.  

As a result, changing between ecosystems is a more onerous and time-consuming process that could lock people into their current platform, even when they want to make a switch. That is currently not the case, since passwords tend to be easier to transfer.

For its part, the FIDO Alliance has stated that batch exporting will likely become a bigger priority in the future. The tech giants have similarly expressed an interest in interoperability. Having said that, the Alliance does not want to make it too easy to exchange passkeys, since that could create a mechanism that hackers could exploit if it is rolled out carelessly.

Sources: Fast Company and Payments Journal

Filed Under: Industry News Tagged With: 2FA, Apple, Biometric, biometrics, CTAP2, cybersecurity, facial recognition, FIDO Alliance, FIDO2, Google, International Association for Cryptologic Research, interoperability, Microsoft, strong online authentication

Related News & Articles

UK’s Digital Employee Verification Rules Come Into Effect

UC San Francisco Project Looks to Biometric Data to Track COVID-19 Spread

Smart Engines Provides Document Scanning Services for Kazakhstan Travel Agency

Primary Sidebar

Learn About Mobile ID and Aviation

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • NordPass, Yahoo! Japan, and Regula Keep Up Mobile Biometrics Momentum
  • NordPass Enables Biometric, TOTP-secured 2FA for Business Users
  • Mastercard Solution Certified Under UK’s Digital ID Framework
  • Transatlantic Digital Traveler Identity Project Gets High-Profile Tech Partner
  • Digital Identity Tech Demo Online Event

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld