LUKS disk encryption with FIDO2
ID: 3db94709-d8d5-5982-88ee-6c939b4e5fc4
STIX ID: report--3db94709-d8d5-5982-88ee-6c939b4e5fc4
Feed Name: Kudelski Security
This report examines using FIDO2 hmac-secret credentials to unlock LUKS-encrypted disks, demonstrating that some authenticators and CTAP implementations can allow disk decryption without requiring a PIN (or with inconsistent user verification), potentially enabling an attacker who obtains both the disk and the token to decrypt data. The authors show experimental results across devices, explain the CTAP 2.1 fix (separate CredRandom values for UV vs non-UV), and recommend using updated authenticators and proper credential creation to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
