Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Compact electric cargo bike fits in your closet
    • Blackbird leads $14 million Seed round for the ‘Canva of financial advice’
    • This Summer, the American Water Crisis Becomes Real
    • US officials are preparing a wide-ranging AI policy memo that outlines rules for national security agencies’ AI use, including avoiding single vendors (Bloomberg)
    • Microsoft Is All-In on Agentic AI and Vibe Coding Now That It’s ‘Working’
    • Two Cases Where Simulation Fills the Gap
    • DeepSeek’s new AI model is rolling out quietly, not to the Wall Street market shock
    • TOI-201 system shows planets changing orbits in real time
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Thursday, April 30
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Phishers have found a way to downgrade—not bypass—FIDO MFA
    News

    Phishers have found a way to downgrade—not bypass—FIDO MFA

    Editor Times FeaturedBy Editor Times FeaturedJuly 18, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    Researchers not too long ago reported encountering a phishing assault within the wild that bypasses a multifactor authentication scheme based mostly on FIDO (Quick Identification On-line), the industry-wide commonplace being adopted by 1000’s of websites and enterprises.

    If true, the assault, reported in a weblog put up Thursday by safety agency Expel, could be large information, since FIDO is extensively considered being resistant to credential phishing assaults. After analyzing the Expel write-up, I’m assured that the assault doesn’t bypass FIDO protections, no less than not within the sense that the phrase “bypass” is usually utilized in safety circles. Relatively, the assault downgrades the MFA course of to a weaker, non-FIDO-based course of. As such, the assault is best described as a FIDO downgrade assault. Extra about that shortly. For now, let’s describe what Expel researchers reported.

    Abusing cross-device sign-ins

    Expel mentioned the “novel assault method” begins with an e-mail that hyperlinks to a faux login web page from Okta, a extensively used authentication supplier. It prompts guests to enter their legitimate consumer title and password. Individuals who take the bait have now helped the assault group, which Expel mentioned is called PoisonSeed, clear the primary massive hurdle in gaining unauthorized entry to the Okta account.

    The FIDO spec was designed to mitigate exactly these types of situations by requiring customers to offer a further issue of authentication within the type of a safety key, which is usually a passkey, or bodily safety key corresponding to a smartphone or devoted system corresponding to a Yubikey. For this extra step, the passkey should use a singular cryptographic key embedded into the system to signal a problem that the positioning (Okta, on this case) sends to the browser logging in.

    One of many methods a consumer can present this extra issue is by utilizing a cross-device sign-in characteristic. Within the occasion there is no such thing as a passkey on the system getting used to log in, a consumer can use a passkey for that website that’s already resident on a distinct system, which typically might be a cellphone. In these circumstances, the positioning being logged into will show a QR code. The consumer then scans the QR code with the cellphone, and the traditional FIDO MFA course of proceeds as regular.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    US officials are preparing a wide-ranging AI policy memo that outlines rules for national security agencies’ AI use, including avoiding single vendors (Bloomberg)

    April 30, 2026

    OpenAI says its models, starting with GPT-5.1, “increasingly mentioned goblins, gremlins, and other creatures”, leading to prompt instructions to mitigate it (OpenAI)

    April 30, 2026

    CFTC Sues Wisconsin in Escalating Fight Over Prediction Market Regulation

    April 30, 2026

    US soldier pleads not guilty in first prediction market insider trading case tied to Polymarket bets

    April 30, 2026

    Resorts World NYC opens first full casino in New York City with live table games in Queens

    April 30, 2026

    Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

    April 29, 2026

    Comments are closed.

    Editors Picks

    Compact electric cargo bike fits in your closet

    April 30, 2026

    Blackbird leads $14 million Seed round for the ‘Canva of financial advice’

    April 30, 2026

    This Summer, the American Water Crisis Becomes Real

    April 30, 2026

    US officials are preparing a wide-ranging AI policy memo that outlines rules for national security agencies’ AI use, including avoiding single vendors (Bloomberg)

    April 30, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Volkswagen Multivan eight-seat MPV camper van

    June 14, 2025

    Self-healing composite materials for machines to last centuries

    February 23, 2026

    Super Technologies expands Sportradar partnership to power global betting growth

    March 3, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.