You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The classical enrollment of smartphone apps like specified by Google, which contains the key material in the QR code, is prone to copy-attackers.
We could remove the key material from the QR code. The QR code could only contain a URL to the privacyIDEA server, a kind of on-time registration URL. The Smartphone would generate the key material and pass the key material to this very URL.
Problem
An attacker could still scan the QR/URL and pass his own key material.
Mitigations
The enrolled key material could be deactivated.
Additional means to enable the key material or protect the URL like additional credetials.
This could be
know
sent by snail mail
sent via SMS...
The user would then have to enter e.g. the credentials during the enrollment --- on the smartphone?
The text was updated successfully, but these errors were encountered:
The classical enrollment of smartphone apps like specified by Google, which contains the key material in the QR code, is prone to copy-attackers.
We could remove the key material from the QR code. The QR code could only contain a URL to the privacyIDEA server, a kind of on-time registration URL. The Smartphone would generate the key material and pass the key material to this very URL.
Problem
An attacker could still scan the QR/URL and pass his own key material.
Mitigations
The enrolled key material could be deactivated.
Additional means to enable the key material or protect the URL like additional credetials.
This could be
The user would then have to enter e.g. the credentials during the enrollment --- on the smartphone?
The text was updated successfully, but these errors were encountered: