logo

Unprotected Session Tokens Can Undermine FIDO2 Security

ID: c7f05f41-0899-55de-a9a8-d8f361728977

STIX ID: report--c7f05f41-0899-55de-a9a8-d8f361728977

Feed Name: Dark Reading

Threat Score
50/100

Date Published: 2024-05-14

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Silverfort's analysis warns that while FIDO2 effectively protects the authentication step, many implementations fail to protect the post-authentication session tokens; an attacker who achieves a man-in-the-middle position (via DNS/DHCP spoofing, ARP poisoning, SLAAC, etc.) can steal unbound session tokens and hijack SSO access. The report found that tested vendors (Yubico, EntraID, Ping) successfully secured authentication but still exposed sessions to token theft, and experts urge enabling token binding and improving session protection to mitigate this risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.