Passkey sign ups are at risk of account pre‑hijacking #4452
Replies: 1 comment
-
|
Hello @chrisciszak The scenario you described is a bit of niche edge case, because it requires the attacker to re-check if they can login already, and the enduser to ever actually verify her address. But with some targeted social engineering this could be feasible. To solve the specific scenario that you described there would need to be additional verification steps during registration and only if the end-user passes the verification the record is created in the DB. The only way this can be solved right now is to force the user to review all auth methods on every login. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hey
Can someone explain why Ory would allow to sign up with passkey using an email without actually verifying the ownership of the email first?
Imagine the following scenario where I managed to hijack an account:
Should't the passkey sign up have a required step to verify email ownership via OTP before the passkey is considered valid?
Require email verification before login doesn't solve this as passkeys bypass this anyway.
Beta Was this translation helpful? Give feedback.
All reactions