Reviewing security postures and attacks on various 2FA (2-factor authentication) means, including security keys and passkeys. (OWASP Saitama MTG #27, talk #1)
METI CTFCJ 2012 Qual.: Won ▸ METI CTFCJ 2012: 3rd ▸ DEF CON 21 CTF: 6th ▸ DEF CON 22 OpenCTF: 4th ▸ ൃදɾߨԋͳͲ DEF CON 25 Demo Labs (2017) DEF CON 27 AI Village (2019) CODE BLUE (2017, 2019) CYDEF (2020) etc. “DEFCON 2016” by Wiyre Media, CC BY 2.0
▸ #1: what you know →password / passphrase ▸ #2: what you have →ܭࢉೳྗػࡐͳͲʢ←TOTP, SMS etc.ʣ ▸ #3: what you are →ੜମͷಛʢ←ࢦ, ࠼, إ, etc.ʣ “M&S Bank 2FA output” by Orde Saunders, CC BY 2.0
TOTP: ࣌ࠁ: challenge, OTP: response ▸ SMS: ཚ: challenge/response ▸ ͕ͩ: Ϣʔβ=ਓ͕ؒհ →߈ܸऀ͕डྖͰ͖Εೝূཱ →ʮೝূ൪߸Λڭ͑ͳ͍ͰʂʯͱݴΘΕΔཧ༝ “Writing Up Challenge Responses” by Alan Levine, CC BY 2.0
▸ USB/NFCͰଓͯ͠ػೳ (※Bluetoothଓͷͷ͔ͭͯ͋ͬͨ) ▸ ެ։伴҉߸ܥͰೝূओମͱσόΠεͷਖ਼ੑ Λ૬ޓೝূ →࣮࣭తͳfactor #2ͱͯ͠ػೳ (U2F=Universal 2nd Factor [FIDO Alliance]) “Yubikey USB 2FA U2F Security Token” by Tony Webster, CC BY 2.0
ެ։伴҉߸ܥʹΑΔೝূͳͷͰ҆શ →͏ʔΜ…ͳʹ͕Ͳ͏҆શͳΜͩ… ▸ ੜମೝূͰϩάΠϯͰ͖ΔͷͰ҆શ →͏ʔΜ…ͦΕ࣮ͷͩ… ▸ ύεϫʔυΛΘͳ͍ͷͰ҆શ etc. →͏ʔΜ…ࣗಈతʹ҆શʹͳΔΘ͚Ͱ… “Contraseña / Password” by Microsiervos, CC BY 2.0
AppleͳͲͷऔΓѻ͍) ▸ Bluetooth FIDOσόΠεͲ͏ͳ͔ͬͨʁ →iOS/AndroidʹΑΔauthenticatorͱՁ →ͪ͜Βʹٵऩ͞Εͯ͠·ͬͨՄೳੑ “Gettysburg Address: fountain pen handwriting practice” by Stephen Little, CC BY-NC 2.0
(ʹඇଋറత) →ͷຊ࣭; SMSSIM swappingͳ͠Ͱ… ▸ Security Keys/Passkeys2FAΛਖ਼͘͠Δͷ →ର·ͱΊͯॺ໊; ೝূཁૉଋറ →SK: USB/NFC+HSM, PK: BLE+Local KS →΄΅ಉ͡ͷ͕ͩSKʹ·ͩҰͷ͕͋Δ “Writing Up Challenge Responses” by Alan Levine, CC BY 2.0
2.2: epochͷنఆ͕optional) ▸ τϯωϧͷਖ਼ੑ୲อʹؔ͢Δنఆ͕ͳ͍ →Ephemeral Keysͷ༻ͳͲ͕ඞཁͳͷͰ →͘͠epochΛඞਢʹ͢ΔͳͲ “Yahoo! delivers amazing new experiences via Android and HTML5” by Yahoo, CC BY 2.0
All Mobile Browsers", Tobia Righi, February 2025. https://mastersplinter.work/research/passkey/ “look at alll the papers!” by Sara Grajeda, CC BY-NC-SA 2.0