Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Zeroizing vs. reuse of activation factors #1962

Open
jimfenton opened this issue Feb 27, 2020 · 0 comments
Open

Zeroizing vs. reuse of activation factors #1962

jimfenton opened this issue Feb 27, 2020 · 0 comments

Comments

@jimfenton
Copy link
Member

-63B Section 5.1.9.1 says:

Each authentication operation using the authenticator SHOULD require the input of the additional factor.

This seems somewhat at odds with a later statement in the section:

The unencrypted key and activation secret or biometric sample — and any biometric data derived from the biometric sample such as a probe produced through signal processing — SHALL be zeroized immediately after an authentication transaction has taken place.

If the latter statement is a SHALL, it seems like the earlier one would need to be a SHALL as well. It's possible that the activation factor is resent from the host endpoint being authenticated, and that the zeroization requirement doesn't apply there. But this should be clarified.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants
@jimfenton and others