Phishers have found a way to downgrade—not bypass—FIDO MFA
222d ago
Technology
Ars Technica

Recent reports suggesting the complete circumvention of FIDO multi-factor authentication (MFA) by phishing attacks have been clarified. Instead of bypassing FIDO MFA entirely, phishers are employing a technique to downgrade the authentication process to a less secure method. This nuanced attack exploits vulnerabilities in fallback mechanisms, emphasizing the importance of robust security configurations and user awareness training to prevent successful phishing attempts and maintain the integrity of FIDO MFA implementations. Users should remain vigilant and ensure they are using the strongest authentication methods available.