Master thesis : FIDOLOGY : A Measurement Study of FIDO2 Adoption Across the Web
Krumm, Macha
Promotor(s) :
Donnet, Benoît
Date of defense : 29-Jun-2026/30-Jun-2026 • Permalink : http://hdl.handle.net/2268.2/26194
Details
| Title : | Master thesis : FIDOLOGY : A Measurement Study of FIDO2 Adoption Across the Web |
| Translated title : | [fr] FIDOLOGIE : Étude quantitative sur l'adoption de FIDO2 sur le Web |
| Author : | Krumm, Macha
|
| Date of defense : | 29-Jun-2026/30-Jun-2026 |
| Advisor(s) : | Donnet, Benoît
|
| Committee's member(s) : | Mathy, Laurent
Fontaine, Pascal
|
| Language : | English |
| Number of pages : | 109 |
| Keywords : | [en] FIDOLOGY [en] FIDO2 [en] password [en] authentication [en] signals [en] classification [en] challenge |
| Discipline(s) : | Engineering, computing & technology > Computer science |
| Target public : | Researchers Professionals of domain Student General public |
| Institution(s) : | Université de Liège, Liège, Belgique |
| Degree: | Master : ingénieur civil en informatique, à finalité spécialisée en "computer systems security" |
| Faculty: | Master thesis of the Faculté des Sciences appliquées |
Abstract
[en] The FIDO2 standard enables passwordless user authentication using security tokens and combines the Web Authentication specification (WebAuthn) with the new Client-to-Authenticator Protocol (Ctap2) protocol. Since its launch in 2018, websites have gradually begun to adopt it, but to date, the real state of adoption of FIDO2 in the wild is not known.
This work aims to fill this gap by creating Fidology, a tool that categorizes the authentication mechanisms implemented by websites into five categories, by implementing,
in a non-intrusive and deterministic way, an automated pipeline using headless browser
and multi-layered signals inference. First applied to a manually crafted groundtruth and then evaluated against a much larger dataset, this tool has shown that classical password-based mechanisms continue to dominate the world of authentication, whilst FIDO2 clues are detected on a small but non-negligible proportion of websites.
In addition to this state of FIDO2 deployment, authentication flows are captured to
analyse cryptographic challenges and other metrics, with the aim to evaluate the security
level of websites previously identified as belonging to the FIDO2-Native category. While
most of them meet, and and in some cases even exceed, the expected Fido requirements,
critical issues like challenge reuse across sessions are discovered.
File(s)
Document(s)
Cite this master thesis
The University of Liège does not guarantee the scientific quality of these students' works or the accuracy of all the information they contain.

Master Thesis Online


All files (archive ZIP)
Master_Thesis_Krumm.pdf