Sept. 21, 2023, 6:12 p.m. |

IACR News www.iacr.org

ePrint Report: To attest or not to attest, this is the question – Provable attestation in FIDO2

Nina Bindel, Nicolas Gama, Sandra Guasch, Eyal Ronen


FIDO2 is currently the main initiative for passwordless authentication in web servers. It mandates the use of secure hardware authenticators to protect the authentication protocol’s secrets from compromise. However, to ensure that only secure authenticators are being used, web servers need a method to attest their properties. The FIDO2 specifications allow for authenticators and web …

attestation authentication authenticators eprint report fido2 hardware initiative main passwordless passwordless authentication question report servers web

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Open-Source Intelligence (OSINT) Policy Analyst (TS/SCI)

@ WWC Global | Reston, Virginia, United States

Security Architect (DevSecOps)

@ EUROPEAN DYNAMICS | Brussels, Brussels, Belgium

Infrastructure Security Architect

@ Ørsted | Kuala Lumpur, MY

Contract Penetration Tester

@ Evolve Security | United States - Remote

Senior Penetration Tester

@ DigitalOcean | Canada