Closed Bug 1711427 Opened 3 years ago Closed 2 years ago

CBOR decoding checks differ between Chrome and Nightly for Feitian ePass FIDO2 NFC (K9) key

Categories

(Core :: DOM: Web Authentication, defect)

Firefox 90
defect

Tracking

()

RESOLVED INVALID

People

(Reporter: jimdoe, Unassigned)

References

Details

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0

Steps to reproduce:

Register Feitian ePass FIDO2 NFC (K9) key as per https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-security-key#user-registration-and-management-of-fido2-security-keys

Actual results:

Key was successfully registered

Expected results:

key should not have registered as per reasons suggested by Chrome/Brave/Edge style Chromium based browsers. They report in the chrome://device-log for FIDO events the following.

FIDOError[2021/05/14 19:42:01.198392] type_conversions.cc:242 Unexpected CtapDeviceResponseCode: 18

FIDOError[2021/05/14 19:42:01.198289] authenticator_data.cc:72 CBOR decoding of authenticator data extensions failed (Map keys must be strictly monotonically increasing based on byte length and then by byte-wise lexical order.) from A26B686D61632D736563726574F56B6372656450726F7465637401

Windows 10 reports in its webathn event log the following for a successful registration attempt when using Firefox.

Cbor decode MakeCredential response.

TransactionId: {2dfd0a73-3615-4016-83bc-7367edb2a138}
AttestationFormatType: packed
RpIdHash: 0xE1011854B4CEA0CE26B2AA5AB433C24DC130031C242DBE6E386A6B99D395ADDC
Flags: 0xC5
SignCount: 0xB2
AAGuid: {ee041bce-25e5-4cdb-8f86-897fd6418464}
CredentialId: 0xAE81D1084F3DCB6656D619238F3175095A84E27DDA3F06B1B98DAC81D3A841F9
U2fPublicKey: false
PublicKey: 0xA50102032620012158200C3B2BC22033E36612A967DB4A760D59E8E6DB84B4E56CD49F5FE10D04CD3B56225820DC6DB3A7AA8F3B246EEC56E0F85328EB14944A006EAEA3E275BE34429BF97484
Response: 0x

Windows logs the following for Edge for a failed attempt (corresponding to FIDO log extract pasted above).

Cbor decode MakeCredential response.

TransactionId: {2fc36489-d82a-4f6b-b136-b9439efbdf58}
AttestationFormatType: packed
RpIdHash: 0xE1011854B4CEA0CE26B2AA5AB433C24DC130031C242DBE6E386A6B99D395ADDC
Flags: 0xC5
SignCount: 0x177
AAGuid: {ee041bce-25e5-4cdb-8f86-897fd6418464}
CredentialId: 0xED3B8390E6EA0EA4FE2C70047DA0B8580AE69207439A72EE6221CF48AFD0D4CF
U2fPublicKey: false
PublicKey: 0xA50102032620012158202C9493F4F53BE436EBF861017F692B6C8708974533504F99C24C84466528BB9B225820CD1AC9249A175CB96F1640F825545A83602494D9AC4C637CB777737DD58E5859
Response: 0x

I am not sure if fault is within Chrome or Firefox yet.
Can you please validate the observations and determine if the key registration should have succeeded in Firefox?

The Bugbug bot thinks this bug should belong to the 'Core::Audio/Video: Playback' component, and is moving the bug to that component. Please revert this change in case you think the bot is wrong.

Component: Untriaged → Audio/Video: Playback
Product: Firefox → Core
Component: Audio/Video: Playback → DOM: Web Authentication

Seems related to how WEBAUTHN_EXTENSIONS_IDENTIFIER_CRED_PROTECT extension is handled between Chrome based browsers vs Firefox.

The authentication extensions don't have anything related to WEBAUTHN_EXTENSIONS_IDENTIFIER_CRED_PROTECT when the key is used with Firefox. But when Chrome/Edge/Brave are used WEBAUTHN_EXTENSIONS_IDENTIFIER_CRED_PROTECT is present.

I am new to CBOR specs and WebAuthn so am learning on the fly.
I'm keen to hear the conclusions from someone once this item is triaged :)

I got confirmation from Feitian that this is a fault in their K9 key 2019 model.

This is known issue. FEITIAN has updated recently (Dec 2020). Below is the issue summary:
FEITIAN released the FIDO2 security key in 2019. And at that time, FEITIAN tested all use cases and there was no issue.
But afterwards, Chrome browser updated and Microsoft Edge moved to Chromium Edge. Then this issue arose.
This is related to credProtect, which is not sorted canonically.
Thanks,
Nick
FEITIAN Technologies

Severity: -- → S3
Status: UNCONFIRMED → RESOLVED
Closed: 2 years ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.