A security architect is designing a new authentication system for a high-security environment. The system must support passwordless authentication while providing strong protection against phishing attacks. Which of the following protocols best meets these requirements?
Trap 1: Kerberos with PKINIT
Kerberos with PKINIT uses certificates but still requires a password or PIN for the private key.
Trap 2: TOTP/HOTP
TOTP/HOTP require a shared secret and are susceptible to phishing if the token is intercepted.
Trap 3: X.509 certificates with smart cards
X.509 certificates provide strong authentication but are not passwordless; they require a PIN or biometric.
- A
Kerberos with PKINIT
Why it fails: Kerberos with PKINIT uses certificates but still requires a password or PIN for the private key.
- B
FIDO2/WebAuthn
FIDO2/WebAuthn binds credentials to the origin and uses public-key cryptography, so a phishing site cannot replay the assertion. The private key stays on the authenticator, defeating credential harvesting and enabling passwordless login, which satisfies both the phishing-resistance and passwordless constraints.
- C
TOTP/HOTP
Why it fails: TOTP/HOTP require a shared secret and are susceptible to phishing if the token is intercepted.
- D
X.509 certificates with smart cards
Why it fails: X.509 certificates provide strong authentication but are not passwordless; they require a PIN or biometric.