PoisonSeed and FIDO Replace – Bredemarket


Replace to my July 21 publish “PoisonSeed: Cross-Machine Authentication Shouldn’t Enable Authentication on a Fraudster’s Machine.” FIDO’s cross-device authentication is NOT inherently insecure.
From Chris Burt at Biometric Replace:
“A reported passkey vulnerability has been walked again, and FIDO is advisable because the repair to the vulnerability of “phishable” MFA wreaking havoc on company networks around the globe.
“The PoisonSeed assault reported by safety firm Expel earlier this month doesn’t give entry to protected property, if the FIDO Cross-Machine Authentication circulate is correctly applied.”
Correct implementation and configuration is important.