Stealing cookies: Researchers describe how to bypass modern authentication
https://cyberscoop.com/stealing-cookies-researchers-describe-how-to-bypass-modern-authentication/
https://cyberscoop.com/stealing-cookies-researchers-describe-how-to-bypass-modern-authentication/
2 Comments
tedu@azorius.net · 11 pts · 2y
Well, okay. Maybe there's something new here, but despite the many paragraphs of exposition, this sounds like exactly the sort of cookie stealing attack that's been possible for decades.
Is the big breakthrough here that somebody realized FIDO doesn't change that? Like, uh, no kidding? What's new?
jax@lemmy.cloudhub.social · 4 pts · 2y
Yeah, this seems like old news - cookies can be stolen, and FIDO doesn't change that unless you are prompting the hardware token for validation with every request (which isn't feasible for most things, though might be a good idea for sensitive actions).