No, phishers arenotbypassing FIDO MFA, at least not yet. Here’s why.

No, phishers arenotbypassing FIDO MFA, at least not yet. Here’s why.

Recent findings have brought attention to a phishing method that claims to circumvent the multifactor authentication (MFA) protocols established by FIDO (Fast Identity Online), a standard embraced by numerous companies and websites. If verified, this revelation could significantly impact the cybersecurity landscape, as FIDO is often viewed as a robust defense against credential theft. However, a closer examination of the report published by security firm Expel suggests a different narrative. Instead of outright bypassing FIDO’s security, the technique appears to downgrade the MFA process to a less secure, non-FIDO method. This particular tactic is more accurately characterized as a FIDO downgrade attack. Expel outlined the mechanics of this emerging threat, which begins with an email luring recipients to a counterfeit login page resembling that of Okta, a prominent authentication service. Users who unknowingly enter their credentials effectively assist the attackers, identified as PoisonSeed, in surmounting a critical barrier to accessing the targeted Okta account. The FIDO specification is explicitly designed to address this type of vulnerability by mandating an additional authentication factor, typically a security key that could be a passkey or a physical device like a smartphone or a YubiKey. This extra step involves the passkey generating a unique cryptographic key that signs a challenge issued by the site, in this instance, Okta. Users can authenticate across devices by utilizing a feature that allows them to access a passkey stored on another device, most often their smartphone. When this scenario occurs, the site presents a QR code for the user to scan with their phone, allowing the usual FIDO MFA process to unfold seamlessly.

Sources : Ars Technica

Published On : Jul 18, 2025, 19:10

Mobile
Get Ready for Realme 16 Pro+ 5G: Specifications Unveiled Ahead of Launch

Realme is gearing up to introduce its latest series with the Realme 16 Pro 5G and the Realme 16 Pro+ 5G set to debut on ...

Business Today | Dec 29, 2025, 12:25
Get Ready for Realme 16 Pro+ 5G: Specifications Unveiled Ahead of Launch
Mobile
Celebrate the New Year with WhatsApp's Exciting New Features

WhatsApp is rolling out an array of festive features just in time for New Year’s celebrations. The messaging app, owned ...

Mint | Dec 29, 2025, 15:25
Celebrate the New Year with WhatsApp's Exciting New Features
AI
Explore the New ChatGPT Integrations: Your Personal Assistant for Everything from Travel to Meal Planning

OpenAI has unveiled a suite of app integrations within ChatGPT, allowing users to seamlessly connect their accounts and ...

TechCrunch | Dec 29, 2025, 16:10
Explore the New ChatGPT Integrations: Your Personal Assistant for Everything from Travel to Meal Planning
AI
Box CEO Argues AI Will Ignite Job Creation, Not Elimination

In a bold assertion, Aaron Levie, co-founder and CEO of Box, suggests that the rise of artificial intelligence will not ...

Business Insider | Dec 29, 2025, 13:45
Box CEO Argues AI Will Ignite Job Creation, Not Elimination
Streaming
Must-Watch Streaming Releases This Week: Epic Endings and New Beginnings

As we kick off 2026, a variety of online streaming services are set to launch compelling new content, including gripping...

Business Today | Dec 29, 2025, 11:25
Must-Watch Streaming Releases This Week: Epic Endings and New Beginnings
View All News