How does FIDO2 protect against network-based replay attacks during authentication?
-
A
The server issues a random challenge per ceremony; the authenticator signs it so each response is unique
-
B
TLS session tickets prevent replay at the transport layer
-
C
The credential ID rotates on each authentication
-
D
The relying party uses IP geolocation to detect replays