FIDO2's Real Weakness Is the Environment Around It, Not the Cryptography
arXiv 2609.03789 reassesses the FIDO2/WebAuthn threat model and argues several commonly assumed security properties do not hold under realistic deployment, examining eight attack vectors across the stack: malicious browser extensions, platform-handler malware, passive sniffing, virtual device drivers, CTAP2-specific malware, USB and hardware implants, malicious USB hubs, docks and extenders, and NFC relay attacks. The analysis demonstrates that AAGUID and timing information enable user profiling and targeted attacks, and that compromise of browser, OS or hardware undermines FIDO2 even with uncompromised cryptographic primitives. Attack chains spanning multiple layers can bypass the intended guarantees, which matters because phishing-resistant hardware authentication is frequently sold as security by design.
↳ Follow the thread