Relaying Yubikeys
cube0x0.github.io
cube0x0.github.io
WebAuthN is meaningfully phishing-safe. You can’t replay a login for attacker.com to example.com. What part 1 is demonstrating is that if you compromised the victim’s machine you can arbitrarily use a token for as long as it’s connected. What part 2 is demonstrating is that if you choose server-side to allow subdomains (it’s an option!) and then an attacker takes control of https://subdomain.example.com, they can replay a subdomain login against example.com.
Needless to say, your average phisher doesn’t have control over the victim’s machine or one of the target’s subdomains. It’s still interesting because you might encounter a combination of server-side misconfiguration and user controlled subdomains (like the deprecated user.github.com), but far from an indictment of WebAuthN.
Arguing that calling WebAuthN phishing-safe is a “scam” or that 100% phishable TOTP or MFA over Signal (??) is better is detached from reality and harmful. I wish InfoSec didn’t reward these antics.
The objetive of fido2 is to avoid phishing in the scenario of a third party actor trying to authenticate from a terminal that isn't the origin of the token emission, since it has origin binding.
So obviously if the third party actor is acting from a compromised terminal with access to the fido2 key, they can be the origin of the request.
Sources & more info to educate yourself in the matter:
Lawrence systems TLDR version: https://www.youtube.com/watch?v=F_E2LZK-bFk
RSA conference: https://www.youtube.com/watch?v=aMo4ZlWznao
Fido alliance: https://fidoalliance.org/specs/u2f-specs-master/fido-u2f-ove...
One function is 'PIV' - acting as a 'smart card'. When you create or load a key, you can choose whether you want to require a button press or not [1]. They strongly recommend requiring a button press.
No physical button press = an attacker with root can sign things at will.
[1] https://docs.yubico.com/yesdk/users-manual/application-piv/p...
If you choose to not require touch for your Yubikey it's user error
Yubikeys work great if used as designed.
I believe one option on each certificate in the PIV applet is whether or not a "button press" is required for its use. I believe it is recommended that the device attestation certificate at least is not guarded by the button press.
The threat model for yubikeys is to prevent the key being cloned - if it's in your pocket, it's safe. If you plug it in, and authenticate by PIN to the PIV applet, and push the button when prompted, someone may be able to generate a signature.