Feedback

Faculté des Sciences appliquées
Faculté des Sciences appliquées
MASTER THESIS

Master thesis : FIDOLOGY : A Measurement Study of FIDO2 Adoption Across the Web

Download
Krumm, Macha ULiège
Promotor(s) : Donnet, Benoît ULiège
Date of defense : 29-Jun-2026/30-Jun-2026 • Permalink : http://hdl.handle.net/2268.2/26194
Details
Title : Master thesis : FIDOLOGY : A Measurement Study of FIDO2 Adoption Across the Web
Translated title : [fr] FIDOLOGIE : Étude quantitative sur l'adoption de FIDO2 sur le Web
Author : Krumm, Macha ULiège
Date of defense  : 29-Jun-2026/30-Jun-2026
Advisor(s) : Donnet, Benoît ULiège
Committee's member(s) : Mathy, Laurent ULiège
Fontaine, Pascal ULiège
Language : English
Number of pages : 109
Keywords : [en] FIDOLOGY
[en] FIDO2
[en] password
[en] authentication
[en] signals
[en] classification
[en] challenge
Discipline(s) : Engineering, computing & technology > Computer science
Target public : Researchers
Professionals of domain
Student
General public
Institution(s) : Université de Liège, Liège, Belgique
Degree: Master : ingénieur civil en informatique, à finalité spécialisée en "computer systems security"
Faculty: Master thesis of the Faculté des Sciences appliquées

Abstract

[en] The FIDO2 standard enables passwordless user authentication using security tokens and combines the Web Authentication specification (WebAuthn) with the new Client-to-Authenticator Protocol (Ctap2) protocol. Since its launch in 2018, websites have gradually begun to adopt it, but to date, the real state of adoption of FIDO2 in the wild is not known.
This work aims to fill this gap by creating Fidology, a tool that categorizes the authentication mechanisms implemented by websites into five categories, by implementing,
in a non-intrusive and deterministic way, an automated pipeline using headless browser
and multi-layered signals inference. First applied to a manually crafted groundtruth and then evaluated against a much larger dataset, this tool has shown that classical password-based mechanisms continue to dominate the world of authentication, whilst FIDO2 clues are detected on a small but non-negligible proportion of websites.
In addition to this state of FIDO2 deployment, authentication flows are captured to
analyse cryptographic challenges and other metrics, with the aim to evaluate the security
level of websites previously identified as belonging to the FIDO2-Native category. While
most of them meet, and and in some cases even exceed, the expected Fido requirements,
critical issues like challenge reuse across sessions are discovered.


File(s)

Document(s)

File
Access Master_Thesis_Krumm.pdf
Description:
Size: 8.48 MB
Format: Adobe PDF
File
Access Abstract_Krumm.pdf
Description:
Size: 161.26 kB
Format: Adobe PDF

Author

  • Krumm, Macha ULiège Université de Liège > Master ing. civ. inf. fin. spéc. comp. syst. secur

Promotor(s)

Committee's member(s)

  • Mathy, Laurent ULiège Université de Liège - ULiège > Dép. d'électric., électron. et informat. (Inst.Montefiore) > Systèmes informatiques répartis et sécurité
    ORBi View his publications on ORBi
  • Fontaine, Pascal ULiège Université de Liège - ULiège > Dép. d'électric., électron. et informat. (Inst.Montefiore) > Systèmes informatiques distribués
    ORBi View his publications on ORBi








All documents available on MatheO are protected by copyright and subject to the usual rules for fair use.
The University of Liège does not guarantee the scientific quality of these students' works or the accuracy of all the information they contain.