<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mfa on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/mfa/</link><description>Recent content in Mfa on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/mfa/index.xml" rel="self" type="application/rss+xml"/><item><title>FIDO (Fast IDentity Online) / FIDO2</title><link>https://lesitedefrancois.be/en/security/fido/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/fido/</guid><description>&lt;p&gt;&lt;strong&gt;FIDO2&lt;/strong&gt; is the current generation of authentication standards produced jointly by the &lt;strong&gt;FIDO Alliance&lt;/strong&gt; and the &lt;strong&gt;W3C&lt;/strong&gt;, combining two specifications: &lt;strong&gt;WebAuthn&lt;/strong&gt; (Web Authentication API, W3C Level 3, 2025) and &lt;strong&gt;CTAP2&lt;/strong&gt; (Client to Authenticator Protocol 2, FIDO Alliance). Its defining security property is &lt;strong&gt;origin binding&lt;/strong&gt;: every FIDO2 credential is generated and used with a cryptographic binding to the specific Relying Party ID (RP ID — typically the registering domain&amp;rsquo;s origin) encoded into every authentication assertion. An authenticator will refuse to produce an assertion for &lt;code&gt;evil.com&lt;/code&gt; using a credential registered with &lt;code&gt;bank.com&lt;/code&gt;, even if the phishing site presents an identical login page and intercepts the WebAuthn call — the origin check is enforced inside the authenticator, not in JavaScript, and cannot be bypassed by a man-in-the-middle who controls the network or the browser DOM. This property is what makes FIDO2 &lt;strong&gt;phishing-resistant&lt;/strong&gt; by construction, whereas TOTP, SMS OTP, and push-notification MFA are all interceptable by a real-time phishing proxy. FIDO2 is the direct successor to FIDO U2F (Universal 2nd Factor), which provided phishing resistance as a second factor only; FIDO2 extends the model to full passwordless primary authentication.&lt;/p&gt;</description></item></channel></rss>