Open in app

Sign In

Write

Sign In

Ackermann Yuriy
Ackermann Yuriy

476 Followers

Home

About

Apr 6, 2022

My people

My people are killing. My people are dying. My people are watching. Tied hands at the back. Brains on the ground. Bodies everywhere. Bucha is the new definition of the infinite suffering in this insane war. One of the burned woman, could have been my mom. One of the shot…

Ukraine

2 min read

My people
My people
Ukraine

2 min read


Published in WebAuthn Works

·Nov 10, 2021

ITS SINGLE STEP NOT FACTOR — clarifying more FIDO terminology

I keep seeing people mixing up terminologies about FIDO. Single step, single factor. Double step. etc. Here are some popular statements: “One thing that I think confused the reviewer was that the key was doing biometric second factor even on sites that were using Fido as a single factor.” …

Fido2

2 min read

ITS SINGLE STEP NOT FACTOR — clarifying more FIDO terminology
ITS SINGLE STEP NOT FACTOR — clarifying more FIDO terminology
Fido2

2 min read


Published in WebAuthn Works

·Updated Aug 24, 2022

WebAuthn/FIDO —Series Content Page

This is a page that contains links to all our articles on FIDO protocols. Want to help defend Ukraine? Donate to our 501c3 charity, and help us deploying WebAuthn, passkeys, and Yubikeys: Support CyberSecurity of Ukraine Yubico lent technical support and donated 30,000 YubiKeys, to stop hackers from taking over accounts. To date, about…www.ukrainenow.org FIDO Core Introduction to WebAuthn API Demystifying attestation and MDS

Fido

1 min read

WebAuthn/FIDO — Series Content Page
WebAuthn/FIDO — Series Content Page
Fido

1 min read


Published in WebAuthn Works

·May 26, 2021

WebAuthn/FIDO2: What’s new in MDS3? Migrating from MDS2 to MDS3.

It’s a JSON! It looks like MDS2? Nope, that’s MDS3! This is continuation of our series on Webauthn and FIDO2. Recently FIDO Alliance released new version of the metadata specification. And it’s not simple added new fields, and called it day. MDS3 Metadata entirely overhauled schema, deleting old fields, merging…

Fido2

5 min read

WebAuthn/FIDO2: What’s new in MDS3? Migrating from MDS2 to MDS3.
WebAuthn/FIDO2: What’s new in MDS3? Migrating from MDS2 to MDS3.
Fido2

5 min read


Published in WebAuthn Works

·May 24, 2021

WebAuthn/FIDO2: Demystifying attestation and MDS

This is continuation of our series on Webauthn and FIDO2. The fancies of wine are authentic events - Italo Svevo There is no doubt that attestation is a misunderstood and sometimes controversial topic. I’ve been personally present at a few heated discussions, that some might mistaken for an upcoming fight…

Fido2

9 min read

WebAuthn/FIDO2: Demystifying attestation and MDS
WebAuthn/FIDO2: Demystifying attestation and MDS
Fido2

9 min read


May 13, 2021

Why Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a really bad idea

Disclaimer: Thoughts expressed here are my own, and not of my employers. Recently Cloudflare released their FIDO based CAPTCHA replacement. You can read more about it https://blog.cloudflare.com/introducing-cryptographic-attestation-of-personhood/, and try it here https://cloudflarechallenge.com/. In the nutshell the way it works: User gets FIDO CAPTCHA page. 2. User clicks “I am human”. …

Cloudflare

6 min read

Why Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a really bad idea
Why Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a really bad idea
Cloudflare

6 min read


Published in WebAuthn Works

·Jan 1, 2021

WebAuthn/FIDO2: Verifying Apple Anonymous Attestation

Please note that this is an advance post, and requires prior understanding of the FIDO2 attestations. You can read more about them here. The apple does not fall far from the Packed… TPM… As the proverb goes, it’s all almost exactly the same as Packed attestation, with the nonce in…

Fido2

2 min read

WebAuthn/FIDO2: Verifying Apple Anonymous Attestation
WebAuthn/FIDO2: Verifying Apple Anonymous Attestation
Fido2

2 min read


Published in WebAuthn Works

·Oct 28, 2020

Sorting FIDO/CTAP/WebAuthn terminologies

CTAP1 my U2F you FIDO2 CTAP2. If you are confused about all various FIDO terms, you are not alone. Over the years FIDO has expanded from two, to a dozen working groups. Standards started overlapping, having backwards compatibility and everything went terminologically speaking, bonkers. So here is a breakdown: FIDO…

Fido2

4 min read

Sorting FIDO/CTAP/WebAuthn terminology
Sorting FIDO/CTAP/WebAuthn terminology
Fido2

4 min read


Published in WebAuthn Works

·Jan 15, 2019

Introduction to WebAuthn API and Passkey

…or Level 1 Credential Management API extension for Public Key Credentials, and the untold stories of managing credentials in the browser… What should I expect from this article? Learn what FIDO2, Passkey, and WebAuthn are, and how to use them to kill passwords. What is not going to be here? Assertion and attestation verification. This is done by the server and so described in…

Webauthn

19 min read

Introduction to WebAuthn API
Introduction to WebAuthn API
Webauthn

19 min read


Published in WebAuthn Works

·Dec 15, 2018

WebAuthn/FIDO2: Verifying Android KeyStore Attestation

Please note that this is an advance post, and requires prior understanding of the FIDO2 attestations. You can read more about them here. Security, yeah That’s all I want from you, oh now Security, yeah And a little love that will be true, oh — Otis Redding — Security Android…

Security

3 min read

WebAuthn/FIDO2: Verifying Android KeyStore Attestation
WebAuthn/FIDO2: Verifying Android KeyStore Attestation
Security

3 min read

Ackermann Yuriy

Ackermann Yuriy

476 Followers

FIDO, Identity, Standards

Following
  • Ethan Siegel

    Ethan Siegel

  • Kevin Beaumont

    Kevin Beaumont

  • DeveloperSteve

    DeveloperSteve

  • Ministry of Testing

    Ministry of Testing

  • Rowan Livingstone

    Rowan Livingstone

See all (111)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech