CompTIA SecurityX (CAS-005)Security EngineeringHard

A large e-commerce company is experiencing frequent credential stuffing attacks against its customer login portal. The security team has implemented MFA, but attackers are still able to enumerate valid usernames. The company wants to implement a mechanism that cryptographically proves user presence and intent during authentication without relying on traditional passwords or shared secrets, thereby eliminating the ability to enumerate valid usernames through password-guessing attempts. Which of the following technologies would BEST address this specific challenge?

  1. ATime-based One-Time Passwords (TOTP)
  2. BClient-side certificates for mutual TLS
  3. CBiometric authentication with server-side template storage
  4. DWebAuthn with platform authenticators
Show answer & explanation

Correct answer: D. WebAuthn with platform authenticators

WebAuthn (part of FIDO2) with platform authenticators (e.g., built-in fingerprint readers, Windows Hello, Face ID) provides strong, phishing-resistant, passwordless authentication. Critically, during the authentication flow, the user's public key is registered with the server, and a unique cryptographic challenge is signed by the authenticator. This process does not involve sending a username to the server until after a successful cryptographic attestation, making username enumeration via password-guessing attempts impossible because there's no password to guess. It also cryptographically proves user presence and intent.

Why the other options are wrong

  • A. TOTP is a form of MFA that can be bypassed by credential stuffing if the primary factor (username/password) is compromised or if the attacker can intercept the TOTP. It doesn't prevent username enumeration.
  • B. Client-side certificates for mutual TLS provide strong authentication for the client and server but typically require a username or other identifier to be sent during the TLS handshake or application layer for authorization, which could still allow for username enumeration attempts if not carefully designed.
  • C. Biometric authentication with server-side template storage still often relies on a username/password for initial identification, and if templates are stolen, it could lead to other issues. It doesn't inherently prevent username enumeration.

WebAuthn

WebAuthn is a web standard published by the W3C and FIDO Alliance, defining an API that allows web-based applications to integrate with strong authenticators for passwordless or multi-factor authentication.

  • Component of FIDO2, enabling passwordless authentication in browsers.
  • Uses public-key cryptography (asymmetric keys).
  • Authenticators can be hardware tokens, biometrics, or platform-integrated.
  • Provides phishing resistance and prevents username enumeration via password guessing.

Memory trick: WebAuthn's Cryptographic Challenge Stops User Enumeration

More Security Engineering questions