FIDO Cross Device Phishing
TL;DR; This post explains a phishing technique for FIDO cross‑device (hybrid) authentication. An attacker can run an AitM proxy that shows a fake, OS‑like QR code prompt in the browser. The attack requires placing one or more Bluetooth beacons within the victim’s Bluetooth range. See Proof of Concept and Demo Video Housekeeping First of all, I want to make clear that I am 100% convinced of FIDO. That’s a game-changer when it comes to security!...