Simulation of FIDO2/Webauthn #2022
-
Hello everybody, We are going to use Webauthn/FIDO2 to achieve strong authentication but there is a problem! The question is that can an illegal bet website simulate webauthn/FIDO2 Client and Authenticator automatically and create pair key and sign challenge of Relay Party? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Hi @Snbig, I'm not sure if the MSTG is the right place for this question. At least for me, it sounds more like a backend issue. The focus of the MSTG is the mobile apps. Maybe you can contact the ASVS team: https://owasp.org/www-project-application-security-verification-standard/ Join their Slack here: https://join.slack.com/share/enQtMjk3NjY4Njk5MzA1Ni05OTY2ZTcwNzRkNzVjZGU2MWM5ZWZkOWNhNzM4OGRiZmIxNDIxNjlhMTc0YTNhMThkYTk2ODQzYzc5NzRkMmZm |
Beta Was this translation helpful? Give feedback.
Hi @Snbig, I'm not sure if the MSTG is the right place for this question. At least for me, it sounds more like a backend issue. The focus of the MSTG is the mobile apps.
Maybe you can contact the ASVS team: https://owasp.org/www-project-application-security-verification-standard/
Join their Slack here: https://join.slack.com/share/enQtMjk3NjY4Njk5MzA1Ni05OTY2ZTcwNzRkNzVjZGU2MWM5ZWZkOWNhNzM4OGRiZmIxNDIxNjlhMTc0YTNhMThkYTk2ODQzYzc5NzRkMmZm