BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidescbr.com.au//bsides-canberra-2026//speaker//ZH
 7S8U
BEGIN:VTIMEZONE
TZID:Australia/Sydney
BEGIN:STANDARD
DTSTART:20250924T000000
TZNAME:AEST
TZOFFSETFROM:+1000
TZOFFSETTO:+1000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20251005T030000
RDATE:20261004T030000
TZNAME:AEDT
TZOFFSETFROM:+1000
TZOFFSETTO:+1100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20260405T030000
RDATE:20270404T030000
TZNAME:AEST
TZOFFSETFROM:+1100
TZOFFSETTO:+1000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Attacking Passkeys: Offensive Tooling and Implementation Vulnerabi
 lities - Josh
DTSTART;TZID=Australia/Sydney:20260924T161500
DTEND;TZID=Australia/Sydney:20260924T171000
DTSTAMP:20260807T131921Z
UID:pretalx-bsides-canberra-2026-UNKU3E@cfp.bsidescbr.com.au
DESCRIPTION:Passkeys are showing up everywhere\, but how many people can a
 ctually say how they work\, where they break\, or how to test one?\n\nWe'l
 l start with a Passkey 101: what FIDO2\, WebAuthn and CTAP actually are\, 
 and what people mean by "un-phishable."\n\nWith that established\, the pro
 tocol turns out to be the easy part. The security you get depends on the d
 eployment and we will demonstrate it with four attacks. An XSS bug can be 
 enough to plant an attacker's passkey on a victim's account\, and inelegan
 t signature-counter implementation for roaming credentials can allow crede
 ntial replay. A simple but surprising IDOR in WebAuthn payloads can bypass
  poorly-implemented FIDO2 auth\, and in SimpleWebAuthn we found and report
 ed a certificate-chain validation flaw in attestation that let a forged au
 thenticator pass as genuine.\n\nWe will also release two new tools for ins
 pecting and tampering with passkeys\, so you can find these issues in your
  own targets. By the end you'll know where passkey deployments break\, and
  you'll have the tools to prove it.
LOCATION:Off-Main Track
URL:https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UNKU3E/
END:VEVENT
END:VCALENDAR
