Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, I think the protocol protects against MITM and replay attacks. http://fidoalliance.org/specs/fido-security-ref-v1.0-rd-2014...


No, not really - if you're a MITM, you control what the user sees, as well as what gets sent to the device, and nothing prevents those 2 things being different. You might SEE that you're sending $100 to Grandma, but when you tap the key, you're authenticating your entire bank balance to some place in the Bahamas.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: