Zero-knowledge attestation
imperialviolet.org
imperialviolet.org
Are we really building a web where a single organisation gets to decide which devices people can use to access any website securely? I don't know if that's worse than a web where individual sites can say "Only Windows/Android/iOS/WeChat users can create accounts here".
Before long, the requirements for a "secure" device will be one which effectively implements something like DRM (i.e. has secret signing keys outside of your control), probably requiring biometrics (iris scan or fingerprint), and possibly phoning home to a government or corporation, to check for firmware updates or revocation information (i.e. a kill switch, like in AACS).
I think FIDO specifications and most organizations feeling pressure to at least support devices they approve would mostly be good for the user.
The rate FIDO will introduce more invasive behavior instead of user benefiting behavior before there is a version too common for most sites to reject is going to be related to the level proprietary dongles issued by Banks, etc, remain acceptable.
In the FIDO case, the consumer actually is the customer, so negative features will have to arrive by vendors fighting their own customers interests, and pushing institutions to reject their older devices. I think they probably will, but not at the rate they can fight users when the institution is the customer.
This is basically a huge coordination problem, and there are natural barriers to entry against becoming a globally accepted provider of hardware which websites are prepared to trust.
History has shown that, as long as a market appears to have two options, people will be content to choose the lesser or two evils rather than invest time and effort into changing the system to add more options.
On the device side, there are also open source solutions (disclaimer: I work on SoloKeys).
Other than Vanguard, Amazon AWS also temporarily launched support for fido2/u2f only with yubikeys, but soon after they relaxed the requirements. It might be just a marketing/co-sponsorship move.
This is not to say that the risk isn’t there, but support for anonymous attestation is certainly a great feature, and it’s already available (though, not sure if implemented).
As for the problem of user-agent sniffing, well, it is done for a reason. Probably there's less of it these days than there used to be as browsers got better and more standards compliant. I'd be interested to know why Vanguard restrict to YubiKeys, perhaps someone from the FIDO alliance can find out.
[0]:
> When it comes to account security, everyone has a role to play. So we're now requiring you to sign up to receive security codes. These codes provide a type of 2-step verification that adds an extra level of security to your accounts.
You can avoid signing up for 2FA after login by clicking "Get started," then "Cancel" without marking that you agree to the terms, and then manually navigating to your desired URL, e.g., https://personal.vanguard.com/us/myaccounts/balancesholdings .
Perhaps, but often 2FA is leaned on to reduce the significance of the primary factor or shift liability.
> The problem comes when a site allows account resets over SMS because then they've just traded one single factor (a password) for another weaker one (SMS).
Yeah, exactly — that would be one way some "2FA" systems weaken the primary factor.