PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Researchers Suggest Security Upgrades for FIDO2, Warn of Attacks

By Tim Sloane
June 1, 2022
in Analysts Coverage, Authentication, Emerging Payments, Fraud & Security, Security
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Researchers Suggest Security Upgrades for FIDO2, Warn of Attacks

Researchers Suggest Security Upgrades for FIDO2, Warn of Attacks

Apple, Google and Microsoft have all adopted FIDO2 for biometric authentication. This research was the first provable security analysis of this standard and makes recommendations for improvements, especially to strengthen defense against man-in-the-middle attacks. This type of attack is very hard to implement in the wild, but when this authentication method is used to protect highly valuable information, it is likely that additional authentication methods should be utilized. The article also indicates a potential lock-in when a user accumulates many passwords in an environment tied to one specific vendor. In a separate interview with Fast Company, Sam Srinivas, the product management director at Google and current president of the FIDO Alliance, argues: “The platforms do not want to be in a situation where lock-in is a long-term inhibitor for this change in the world, because this is hardly the intent,” he says. “The intent is to make the internet safer.”

“FIDO2 is a passwordless digital ID authentication standard based on public key cryptography that aims for a more secure and easy-to-use online authentication with possession credentials like biometrics. It has seen rapid adoption by popular web browsers, the Android operating system, and various biometric authentication systems like Windows Hello and Keyless.

The researchers write in the paper that there is a lack of analysis on the cryptographic provable security approach to the FIDO2 protocols or the CTAP2, and there are limited results on WebAuthn research. By performing a modular cryptographic analysis of the authentication properties guaranteed by FIDO2 using the provable security approach, the research team sought to uncover vulnerabilities and recommendations to bolster the security of FIDO2.

While WebAuthn’s provable security could be proven, the same could not be said of CTAP2. The team found that CTAP2’s “pinToken” generation at login could be a security vulnerability as it was repeated for subsequent communication, which could compromise security as a whole. It also used an unauthenticated Diffie-Hellman cryptographic key exchange that leaves it vulnerable to man-in-the-middle attacks.”

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: AuthenticationBiometricBiometric AuthenticationBiometricsFIDOMan in the MiddlePasswordPasswordsSecurity

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    ACH Is Thriving, and Banks Are Struggling to Keep Pace

    April 7, 2026
    stablecoins, Klarna

    How Stablecoins Emerged as a Key Element of Cross-Border Payments

    April 6, 2026
    Cross-Border Payments

    How the U.S. Built Its Faster Payments Ecosystem

    April 3, 2026
    Young Latin woman applying powder on her face for beauty blog. Smiling woman sitting at table in cosy room holding powder box and brush looking at phone camera recording video. Make up and cosmetics blogging concept

    TikTok Aspires to Fintech Status with Payments, Credit Bids in Brazil

    April 2, 2026
    small business credit card

    What Banks Get Wrong About Small Business Credit Cards

    April 1, 2026
    embedded payments

    Embedding Payments for Growth: How ISVs Can Scale Through Vertical Focus and Partnerships

    March 31, 2026
    ACH fraud monitoring

    From a Checkbox to a Differentiator: Redefining ACH Fraud Monitoring

    March 30, 2026
    Digitization and Multi-Brand Cards: Prepaid Trends. Bancorp Bank prepaid card fees, Bitpay Prepaid Card, mobile prepaid debit cards, prepaid cards for councils

    Turning a Prepaid Card into a Long-Term Relationship

    March 27, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result