Report URI shares the results of a targeted penetration test on their newly implemented Passkeys (WebAuthn-based 2FA) feature. Eight findings were identified by Pentest Ltd., including empty/overlong/duplicate credential IDs, an origin mismatch bug in the WebAuthn library, cross-origin validation failure, unvalidated user

16m read timeFrom scotthelme.ghost.io
Post cover image
Table of contents
Our annual penetration testsEngaging with PentestThe findings

Sort: