Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Two Cases Where Simulation Fills the Gap
    • DeepSeek’s new AI model is rolling out quietly, not to the Wall Street market shock
    • TOI-201 system shows planets changing orbits in real time
    • How the future of AI is at stake in the legal fight between Elon Musk and OpenAI’s Sam Altman
    • Goal Zero Yeti 1500 Power Station Review (2026): More Power, Better Chemistry
    • OpenAI says its models, starting with GPT-5.1, “increasingly mentioned goblins, gremlins, and other creatures”, leading to prompt instructions to mitigate it (OpenAI)
    • I Replaced Microsoft 365 With This Free Program, and I’m Happy With the Switch
    • Robot vacuum hides in kitchen cabinets for stealthy cleaning
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Thursday, April 30
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Phishers have found a way to downgrade—not bypass—FIDO MFA
    News

    Phishers have found a way to downgrade—not bypass—FIDO MFA

    Editor Times FeaturedBy Editor Times FeaturedJuly 18, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    Researchers not too long ago reported encountering a phishing assault within the wild that bypasses a multifactor authentication scheme based mostly on FIDO (Quick Identification On-line), the industry-wide commonplace being adopted by 1000’s of websites and enterprises.

    If true, the assault, reported in a weblog put up Thursday by safety agency Expel, could be large information, since FIDO is extensively considered being resistant to credential phishing assaults. After analyzing the Expel write-up, I’m assured that the assault doesn’t bypass FIDO protections, no less than not within the sense that the phrase “bypass” is usually utilized in safety circles. Relatively, the assault downgrades the MFA course of to a weaker, non-FIDO-based course of. As such, the assault is best described as a FIDO downgrade assault. Extra about that shortly. For now, let’s describe what Expel researchers reported.

    Abusing cross-device sign-ins

    Expel mentioned the “novel assault method” begins with an e-mail that hyperlinks to a faux login web page from Okta, a extensively used authentication supplier. It prompts guests to enter their legitimate consumer title and password. Individuals who take the bait have now helped the assault group, which Expel mentioned is called PoisonSeed, clear the primary massive hurdle in gaining unauthorized entry to the Okta account.

    The FIDO spec was designed to mitigate exactly these types of situations by requiring customers to offer a further issue of authentication within the type of a safety key, which is usually a passkey, or bodily safety key corresponding to a smartphone or devoted system corresponding to a Yubikey. For this extra step, the passkey should use a singular cryptographic key embedded into the system to signal a problem that the positioning (Okta, on this case) sends to the browser logging in.

    One of many methods a consumer can present this extra issue is by utilizing a cross-device sign-in characteristic. Within the occasion there is no such thing as a passkey on the system getting used to log in, a consumer can use a passkey for that website that’s already resident on a distinct system, which typically might be a cellphone. In these circumstances, the positioning being logged into will show a QR code. The consumer then scans the QR code with the cellphone, and the traditional FIDO MFA course of proceeds as regular.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    OpenAI says its models, starting with GPT-5.1, “increasingly mentioned goblins, gremlins, and other creatures”, leading to prompt instructions to mitigate it (OpenAI)

    April 30, 2026

    CFTC Sues Wisconsin in Escalating Fight Over Prediction Market Regulation

    April 30, 2026

    US soldier pleads not guilty in first prediction market insider trading case tied to Polymarket bets

    April 30, 2026

    Resorts World NYC opens first full casino in New York City with live table games in Queens

    April 30, 2026

    Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

    April 29, 2026

    The European Commission issues preliminary DSA findings against Meta, saying Instagram and Facebook fail to prevent under-13 users from accessing the services (Gian Volpicelli/Bloomberg)

    April 29, 2026

    Comments are closed.

    Editors Picks

    Two Cases Where Simulation Fills the Gap

    April 30, 2026

    DeepSeek’s new AI model is rolling out quietly, not to the Wall Street market shock

    April 30, 2026

    TOI-201 system shows planets changing orbits in real time

    April 30, 2026

    How the future of AI is at stake in the legal fight between Elon Musk and OpenAI’s Sam Altman

    April 30, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    AI Hype: Don’t Overestimate the Impact of AI

    November 11, 2025

    Substack raised $100M from the Chernin Group, a16z, and others, sources say at a $1.1B valuation, as it builds a social network and focuses on advertising (New York Times)

    July 17, 2025

    5 AI Models Tried to Scam Me. Some of Them Were Scary Good

    April 22, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.