Enhancing the Security of WebAuthn Implementations: Addressing the Threat of Phishing Attacks from Subdomains

dc.contributor.authorHagman, Elin
dc.contributor.authorMojtaba, Ataie
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerSheeran, Mary
dc.contributor.supervisorMorel, Victor
dc.date.accessioned2025-09-10T13:59:33Z
dc.date.issued2024
dc.date.submitted
dc.description.abstractThe Fast IDentity Online (FIDO2) standard and its WebAuthn specification provide a robust framework for passwordless authentication, emphasising resistance to phishing attacks. Despite this, subdomain takeover vulnerabilities in real-world applications pose a potential risk to WebAuthn’s claim of phishing resistance. This thesis investigates the feasibility and prevalence of phishing attacks originating from subdomains against WebAuthn implementations. Our Proof of Concept (PoC) demonstrates that WebAuthn implementations can be configured to be vulnerable to phishing attacks originating from subdomains. The demonstration highlights critical conditions that make such an attack successful. An analysis of 135 real-world Relying Party identifiers (RP IDs) revealed over 100,000 subdomains. Among these, numerous dangling DNS records were identified, indicating potential vulnerabilities. However, no evidence of current exploitation was identified during the analysis. Additionally, an evaluation of server-side WebAuthn libraries revealed strong adherence to secure origin validation, which strictly ensures authentication requests come from trusted sources. These findings demonstrate that WebAuthn significantly enhances protection against traditional phishing attacks. However, mitigating more advanced threats, such as those originating from subdomains, requires secure configurations and careful developer practices. Despite the potential risks, WebAuthn remains a strong step forward in the evolution of authentication methods, offering robust security improvements over traditional password-based systems.
dc.identifier.coursecodeDATX05
dc.identifier.urihttp://hdl.handle.net/20.500.12380/310463
dc.language.isoeng
dc.relation.ispartofseriesCSE 24-199
dc.setspec.uppsokTechnology
dc.subjectFIDO2, WebAuthn, Passwordless Authentication, Phishing Resistance, Subdomain Takeover, Vulnerability Analysis, Authentication Security.
dc.titleEnhancing the Security of WebAuthn Implementations: Addressing the Threat of Phishing Attacks from Subdomains
dc.type.degreeExamensarbete för masterexamensv
dc.type.degreeMaster's Thesisen
dc.type.uppsokH
local.programmeComputer science – algorithms, languages and logic (MPALG), MSc

Ladda ner

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Storlek:
2.35 KB
Format:
Item-specific license agreed upon to submission
Beskrivning: