Bug 1922357 Comment 5 Edit History

Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.

> I do not think the QR code scanning webapp is a realistic requirement

That's what I meant.

I don't understand the difference between what I see on my Android device when I scan a QR code to log in, and what the victim in your movie sees.  When I scan the fido link from the QR code I see the "Connecting with your device" toast first, then I get a fingerprint prompt ("use your biometric to continue") that clearly says "Use passkey for webauthn.io". 

In the movie, after the "open in another app" the first thing that comes up is a "Skip the QR code next time" prompt that I never see. THEN the "Connecting with your device" prompt comes up in the movie. A fingerprint prompt does come up, but the text says "CHANGE VERIFICATION METHOD" which I assume is because you agreed to the "skip the QR code" choice. I never see a confirmation prompt that explicitly names webauth.io as the site you're going to submit the passkey to. I understand that in your example you've navigated the victim to webauthn.io and we assume you've socially engineered them to be OK with signing in, but I still want to see that confirmation. Without that you could come up with any number of scams that make the user think they're confirming something innocuous when they're actually entering the passkey for their bank. If I'm out and about minding my own business I don't care how good your scam is, there is no way I'm submitting the passkey for any site important to me when I didn't initiate the transaction.

I even tried changing the in-page Authentication setting on webauthn.io to User Verification "Discouraged" and still my phone made me confirm the choice. Of course an attacker couldn't make a real site do that even if it worked, I just wanted to rule that out as the reason for the difference

Is this a difference in Android version? device vendor? I'm guessing yours is a stock Google Android emulator. My device is a Samsung which does change the stock Android UI in lots of ways, but I thought the WebAuthn dialogs were implemented in Google Play Services and might have been outside the scope of Samsung "OneUI" customizations. In any case they looked exactly like the ones in your movie
I don't understand the difference between what I see on my Android device when I scan a QR code to log in, and what the victim in your movie sees.  When I scan the fido link from the QR code I see the "Connecting with your device" toast first, then I get a fingerprint prompt ("use your biometric to continue") that clearly says "Use passkey for webauthn.io". 

In the movie, after the "open in another app" the first thing that comes up is a "Skip the QR code next time" prompt that I never see. THEN the "Connecting with your device" prompt comes up in the movie. A fingerprint prompt does come up, but the text says "CHANGE VERIFICATION METHOD" which I assume is because you agreed to the "skip the QR code" choice. I never see a confirmation prompt that explicitly names webauth.io as the site you're going to submit the passkey to. I understand that in your example you've navigated the victim to webauthn.io and we assume you've socially engineered them to be OK with signing in, but I still want to see that confirmation. Without that you could come up with any number of scams that make the user think they're confirming something innocuous when they're actually entering the passkey for their bank. If I'm out and about minding my own business I don't care how good your scam is, there is no way I'm submitting the passkey for any site important to me when I didn't initiate the transaction.

I even tried changing the in-page Authentication setting on webauthn.io to User Verification "Discouraged" and still my phone made me confirm the choice. Of course an attacker couldn't make a real site do that even if it worked, I just wanted to rule that out as the reason for the difference

Is this a difference in Android version? device vendor? I'm guessing yours is a stock Google Android emulator. My device is a Samsung which does change the stock Android UI in lots of ways, but I thought the WebAuthn dialogs were implemented in Google Play Services and might have been outside the scope of Samsung "OneUI" customizations. In any case they looked exactly like the ones in your movie

Back to Bug 1922357 Comment 5