Ars OpenForum

Carewolf

Ars Legatus Legionis
10,414
Remember the breathless brouhaha about FIDO2 and passkeys?

This this is what FIDO2 was designed to fight. Specifically making sure the authentication device is within a few feet of the point of access being authenticated.
No amount of 2FA is going to stop this kind of social engineering. The people accessing the system in this case are the people who are allowed to access the system, so they hae the FIDA2 keys already. You would need a system where changes requires review of multiple people to stop that kind of stuff.
 
Upvote
-20 (0 / -20)