© All rights reserved.
Nok Nok Nok Nok
  • Solutions
    • Passwordless Authentication
    • Fraud Detection and Prevention -Testing
    • Passkeys
    • Secure Payments
    • Compliance
    • Professional Services
  • Industries
    • Government
    • E-Commerce
    • Financial Services
    • Mobile Network Operators
  • Products
    • Authentication Cloud
    • S3 Suite
    • Smart Analytics Module
    • Smart Sense Module
    • IoT SDK
  • Resources
    • Demo
    • Demonstration – Testing
    • Videos
    • White Papers
    • Testimonials
  • Company
    • About
    • Team
    • Partners
    • Clients
    • Events
    • News
    • Blog
    • Contact Us
    • Support Services
Free Trial
Sign In
Nok Nok
Home / Opinion / Nok Nok Labs Addresses Potential WebAuthn Protocol Security Concerns

Nok Nok Labs Addresses Potential WebAuthn Protocol Security Concerns

  • Author
    Nok Nok News
  • Published
    12 Sep 2018
  • 0 comments
    Join Conversation
Opinion

A team of researchers at Paragon Initiative recently shared a few security concerns related to some cryptographic algorithms in WebAuthn—a web authentication API protocol. In an August 23 blog post, the Paragon team provided an overview of the potential issues they feel WebAuthn is exposed to as a result of vulnerabilities with underlying or supported algorithms. The research is thorough, and the effort to educate users is admirable. However, the security concerns should also be considered in context and with the understanding that how the protocol is implemented plays a significant role.

WebAuthn specification supports different algorithms, some of which are stronger than others. That is a challenge faced by virtually every standard. Standards bodies typically strive to address the widest possible audience and cover the widest range of products or services in an effort to maximize adoption and market reach. The need for backward compatibility and interoperability with other platforms and standards opens the door to potential weaknesses that exist in legacy or third-party components.

 

It is what you do with the standard that matters.

 

The overall strength of a security solution depends on the availability of necessary security infrastructure elements and—most importantly—the strength of the implementation. A good implementation needs to be flexible and provide a framework to allow service providers to make the best choices based on the strengths of the incoming device requests. In the cases where there are weaker devices involved, additional steps need to be taken to validate incoming data and mitigate the underlying risk.

The article from Paragon raises two primary areas of concern: signature forgery vulnerabilities inherent to RSA PKCS1v1.5 padding, and potential weaknesses in the use of ECDAA. WebAuthn is a web authentication API and web browsers add a layer of complexity, interfaces, and APIs above and beyond the operating system. The expanded attack surface opens the door to a variety of possible attacks that are not a function of WebAuthn itself.

The concerns raised by Paragon are not an issue for products from Nok Nok Labs. Nok Nok Labs has deployed products that implement FIDO protocols globally and at a massive scale for the past 4 years. We endorse high security standards and implementations—and that includes scenarios with WebAuthn as well.

Customers who rely on Nok Nok Labs products can specify acceptable algorithms and authentication characteristics through policy. This enables our customers to detect and potentially block weak implementations and mitigate exposure to risk resulting from weaknesses in specific underlying algorithms. It also allows customers to assign risk scores to specific authenticators that use weak or vulnerable algorithms. Using the risk scores provides an opportunity for customers to require additional step-up authentication for improved security, delay the transaction, or take other appropriate measures to reduce risk and ensure strong security.

Nok Nok Labs gives customers the flexibility to limit exposure to these types of flaws through configuration and policy. We also give customers the ability to identify scenarios that are higher risk and require step-up authentication to provide additional protection.

Nok Nok Labs is a founder and strong supporter of FIDO and we stand by WebAuthn. We also recognize that there are potential security concerns inherent with developing a general standard that provides backwards compatibility and interoperability, and the steps that must be taken at the implementation level to address them.

For further questions or comments, please contact Nok Nok Labs ([email protected]).

Nok Nok News

Related Posts

Quantum is Knocking!
FIDO Alliance Open Banking Opinion

Quantum is Knocking!

When Securing Transactions, Global Experience Gets it Done
Biometrics Opinion

When Securing Transactions, Global Experience Gets it Done

2024 Security Industry Predictions: Consolidation, ROI, and the AI Hype Train
Cybersecurity Opinion

2024 Security Industry Predictions: Consolidation, ROI, and the AI Hype Train

Still not a FIDO believer? Apple Just Made a Big Bet
FIDO Alliance Industry News Opinion

Still not a FIDO believer? Apple Just Made a Big Bet

Leave a Reply (Cancel reply)

Your email address will not be published. Required fields are marked *

*
*

Contact Us

Nok Nok, Inc.
2890 Zanker Rd #203
San Jose, CA 95134

(650) 433-1300

[email protected]

Get Google Maps Directions

Contact and Subscribe

* indicates required

Latest Posts

  • Navigating Cybersecurity in Operational Technology: Insights from the Joint Cyber Defense Collaborative
  • Quantum is Knocking!
  • Nok Nok Announces Innovative Solutions that Simplify Deploying and Managing Passkeys
  • Navigating the Path to Passkeys: One Approach Does Not Fit All

Navigation

  • Subscribe
  • Careers
  • Resources
  • Support

Nok Nok Labs, Nok Nok, and NNL are all trademarks of Nok Nok Labs, Inc. © 2025 Nok Nok Labs, Inc.
FIDO is a trademark of the Fast IDentity Online, (FIDO), Alliance. All rights reserved.
Terms Of Use and Privacy Policy

Demo
Free Trial
Videos
Contact Us
Support

Contact Us: (650) 433-1300 • [email protected]

Copy
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}

Please complete this form to view and download this resource.

Submit to Download Forms

* indicates required
  • 日本語