Project

General

Profile

Actions

action #151666

open

[security] FIDO2 key testing

Added by emiler 6 months ago. Updated 2 months ago.

Status:
Workable
Priority:
Normal
Assignee:
Category:
-
Target version:
-
Start date:
2023-11-29
Due date:
% Done:

0%

Estimated time:
8.00 h
Difficulty:
Tags:

Description

We could cover a new area of testing, which deals with FIDO2 keys. The scope should definitely be, at least, 2FA with web applications, but we could also test resident and non-resident keys for SSH and PGP, which are supported at least by Yubikeys.

Our options would be:

  • Bare-metal test with a physical key attached
  • Using a software FIDO2 key, such as rust-u2f or virtual-fido

References

Actions

Also available in: Atom PDF