Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Suggested edit for U2F/Protocol_details/Overview #169

Open
parkerfinch opened this issue Feb 12, 2019 · 0 comments
Open

Suggested edit for U2F/Protocol_details/Overview #169

parkerfinch opened this issue Feb 12, 2019 · 0 comments

Comments

@parkerfinch
Copy link

I'm confused by the discrepancy between the statement on Yubico's overview:

This means that Example.com cannot know whether User1 and User2 shares the same device.

and section 13.1 of the FIDO U2F overview that says:

13.1 An Origin Can Discover that Two Accounts Share a U2F Device

The "attack" described in the FIDO overview says that Example.com could send User1's key handle to User2, and if the device generates a valid signature then Example.com has discovered that User1 and User2 share the same device. My understanding is that this attack will succeed because the App ID will be the same for each account.

So the suggested edit would be to remove that paragraph or, if it is accurate, include an explanation of why this attack won't work. Thanks!

@Yubico Yubico deleted a comment from birajpaul600 Oct 21, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant