> […] use their hardware authentication key to pass a One Time Password (OTP) to the malicious site. This eventually succeeded, […]
It’s interesting that it succeeded, I was under the impression, making some assumptions that using a Hardware key like Yubikey would prevent such attack since the challenge-response in the browser communication with the key contains the domain (which I assume was different) and hence would fail to generate proper OTP for wrong domain.
I assume they, or their vendor - CircleCI (which i haven’t used), had some older implementation of the standard that maybe relied just on the string generated by the hardware key without challenge-response.
I’m glad they caught it and they immediately see WebAuthn as a good successor. This should definitely prevent such attack vector. Nice.