Skip to content
This repository was archived by the owner on Aug 6, 2024. It is now read-only.
This repository was archived by the owner on Aug 6, 2024. It is now read-only.

Fuzzing test use pinUvAuthToken to check if device is crashed or not #112

Description

@nuno0529

command_state->GetCurrentAuthToken() != initial_pin_token_,

But in ctap2.1 spec, this method won't work due to

6.5.5.7.1. Getting pinUvAuthToken using getPinToken (superseded)
..

  • Create a new pinUvAuthToken by calling resetPinUvAuthToken()

Activity

  1. changed the title [-]fuzz test use pinUvAuthToken to check if device is crashed or not[/-] [+]Fuzzing test use pinUvAuthToken to check if device is crashed or not[/+] on Feb 20, 2021
  2. kaczmarczyck commented on Feb 22, 2021

    @kaczmarczyck
    Contributor

    I'm afraid I'll have to come up with a new solution for CTAP2.1. I need a value that is regenerated on a crash only. Maybe I can use a timed permission that is lost on a crash.

    Worst case, I'll have to call a custom command to get/set an internal bool. And crashes for security keys without it are only detected when the security key stops responding.

  3. self-assigned this
    on Feb 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions