¡Phishers discover how to thwart, not bypass, FIDO multi-factor authentication!

Protect your organization against attacks that degrade FIDO security with Q2BSTUDIO's comprehensive solutions: consulting for authentication hardening, custom software development, implementation of strong policies on aws and azure cloud services, integration of AI agents and projects for

martes, 12 de agosto de 2025 • 3 min read • Q2BSTUDIO Team

Artificial-Intelligence-

Recent reports have generated confusion: ingenious phishing attacks do not defeat FIDO technology but in many cases degrade it—not bypass it—causing an authentication flow to move from a phishing-resistant option to a less secure alternative. Understanding this difference is key to designing effective defenses and for companies to adopt measures that maintain end-user protection.

In technical terms, FIDO and WebAuthn provide key-based authentication, tied to the origin and designed to resist phishing. However, attackers have developed social engineering and redirection variants that induce the user to authenticate on an attacker-controlled channel or to accept a backup method such as OTP, SMS, or a key with lower user verification. The result is not that FIDO's cryptography is broken, but that the session is negotiated toward less secure options due to errors in the authentication flow design or permissive server configurations.

This means that mitigation does not involve abandoning FIDO but rather strengthening policies and implementation. Best practices include requiring user verification when possible, prioritizing keys with resident key, and requiring phishing-resistant authenticators, disabling or limiting OTP or SMS-based fallbacks, and rigorously validating rpId and origin on the server. Additionally, using authenticator metadata, applying allowCredentials to avoid accepting unknown credentials, and monitoring anomalies in login behavior reduces the window of opportunity for these attacks.

From an operational standpoint, there are complementary controls: implementing phishing and traffic anomaly detection, enforcing step-up authentication for sensitive actions, educating users about the danger of consenting to unknown pop-ups, and deploying policies to block legacy methods. Penetration testing and authentication flow reviews allow discovering configurations that permit degradation and correcting them before they are exploited.

At Q2BSTUDIO, we help companies implement robust solutions tailored to their risk: we develop custom applications and custom software with FIDO and WebAuthn integration, offer cybersecurity services and authentication auditing, and design secure infrastructures on aws and azure cloud services. Our artificial intelligence and business intelligence solutions enable detecting fraud patterns, automating response, and improving resilience against phishing attempts.

Our experience in artificial intelligence and AI for businesses facilitates the creation of AI agents that monitor authentications, analyze behaviors, and execute mitigation policies in real time. We combine AI agents with tools such as power bi for business intelligence services that visualize risks, trends, and security metrics, turning data into operational decisions that reduce the likelihood of MFA degradation.

If you need to protect your organization against attacks that degrade FIDO security, Q2BSTUDIO offers comprehensive solutions: consulting for authentication hardening, custom software development, implementation of strong policies on aws and azure cloud services, integration of AI agents, and business intelligence projects with power bi. Custom applications and custom software designed with cybersecurity criteria and backed by artificial intelligence are the best defense against advanced phishing techniques.

We recommend starting with a risk assessment focused on authentication flows, followed by FIDO policy adjustments, removal of insecure fallbacks, and deployment of AI-based detection. Contact Q2BSTUDIO for a practical audit and a personalized roadmap that includes secure development, cloud deployment, and business intelligence capabilities to reduce the impact of phishing and strengthen your organization's authentication.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.