{"id":4306,"date":"2024-07-02T17:05:50","date_gmt":"2024-07-02T22:05:50","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/passkey-redaction-attacks-subvert-github-microsoft-authentication"},"modified":"2024-07-02T17:05:50","modified_gmt":"2024-07-02T22:05:50","slug":"passkey-redaction-attacks-subvert-github-microsoft-authentication","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/02\/passkey-redaction-attacks-subvert-github-microsoft-authentication\/","title":{"rendered":"Passkey Redaction Attacks Subvert GitHub, Microsoft Authentication"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt0be5f9acf3355d4d\/668478b50e577156a2061601\/Passkey%281800%29_ArtemisDiana_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While online accounts are increasingly <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/identity-access-management-security\/how-to-get-started-using-passkeys\" rel=\"noopener\">protected by passkey technology<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, it turns out that many banking, e-commerce, social media, website domain name administration, software development platforms, cloud accounts, and more can still be compromised using adversary-in-the-middle (AitM) attacks that make passkeys moot.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That&#8217;s according to Joe Stewart, principal security researcher with eSentire&#8217;s Threat Response Unit (TRU), who says the problem lies not in the passkeys themselves but in their implementation and the need for account recovery options.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many websites provide less-secure backup authentication methods in the event a user has an issue with their passkey or a lost device, so that accounts don&#8217;t become unrecoverable. Attackers can take advantage of this by simply inserting themselves between the user and the website as they would in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/remote-workforce\/onnx-microsoft-365-accounts-mfa-bypass\" rel=\"noopener\">any AitM scenario<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, then manipulating what the login screen looks like so that the user isn&#8217;t given the passkey option at all.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Since the AitM can manipulate the view presented to the user by modifying HTML, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.atinternet.com\/en\/glossary\/css\/\" rel=\"noopener\">CSS<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and images or JavaScript in the login page, as it is proxied through to the end user, they can control the authentication flow and remove all references to passkey authentication,&#8221; Stewart explained in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.esentire.com\/blog\/securing-passkeys-thwarting-authentication-method-redaction-attacks\" rel=\"noopener\">blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on his findings, which he referred to as &#8220;authentication method redaction attacks.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Using this strategy, they can force a target to downgrade to a less-secure alternative that can be intercepted by the lurking adversary. And that&#8217;s a discovery that &#8220;blows a hole&#8221; in the security conversation around passkeys, Stewart explains to Dark Reading.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We started digging into it and found that some, if not all, of the passkey authentication mechanisms out there, have the same issue where they offer passkeys as one option of many, and that attackers can just simply remove that option, and you&#8217;re left with the less secure methods that give them a wide-open door to account takeover,&#8221; he says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"GitHub, Microsoft Passkey Implementations Susceptible to Attack\">GitHub, Microsoft Passkey Implementations Susceptible to Attack<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In one proof-of-concept (PoC) example of this attack flow, Stewart was able to use the open source Evilginx AitM software to proxy and alter an actual GitHub login page, removing the \u201cSign in with a passkey\u201d text from the page so that a user wouldn&#8217;t see it, and instead giving the option to choose a different way to sign in.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Unless the user specifically remembers that they should see a passkey option, they will most likely simply choose to enter their username and password, which will be sent to the attacker along with the authentication token\/cookies, which the attacker can use to maintain persistent access to the account,&#8221; Stewart says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In another scenario where a passkey is used as a second factor of authentication, Stewart found that once again, it&#8217;s trivial to rewrite the HTML of the page to delete the second-factor passkey authentication method altogether. Or, he explained in the findings, an attacker could &#8220;use injected JavaScript to click on one of the alternate methods, jumping forward in the authentication flow automatically so that the user isn&#8217;t even aware there was a choice.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As he wrote in the post, &#8220;since other second-factor methods, such as an authenticator app or recovery code, are not AitM-resistant, the attacker will once again be able to capture all credentials and tokens\/cookies they require to access the account.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, in a third scenario using a Microsoft consumer account, the passkey sign-in option can again be hidden. However, Microsoft has introduced a new \u201cpasswordless\u201d option that could theoretically negate this style of attack. The bad news? It doesn&#8217;t actually work to thwart passkey redaction, because the passwordless account option requires the use of the Microsoft Authenticator application as the sole method of identity verification \u2014 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/microsoft-10k-orgs-hit-in-attacks-that-bypasses-multifactor-authentication\" rel=\"noopener\">a flow that&#8217;s still vulnerable to AitM attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Stewart explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As mentioned, GitHub and Microsoft are not alone; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/passkeys-cool-but-not-ready-for-enterprises\" rel=\"noopener\">most large retailers and cloud app providers <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">have the same issue.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Not a Vulnerability but a Sad Reality\">Not a Vulnerability but a Sad Reality<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Stewart stresses that authentication method redaction attacks succeed not because there are flaws in passkey implementations or because of security bugs but because of authentication immaturity in general.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For one, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/new-developer-tools-necessary-passkey-adoption\" rel=\"noopener\">most users aren&#8217;t familiar enough with passkeys yet<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and don&#8217;t know how to recognize when a page might be manipulated; for another, implementers may not be aware of how AitM can modify the login view. And the fact remains that offering account recovery options is a must; passkeys are housed on hardware devices so if the device is lost, then there needs to be another way to access the account. Unfortunately, those backups are nearly always vulnerable to AitM.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If it weren&#8217;t for the need for account recovery, an AitM-resistant passkey authentication flow could be fairly straightforward, abandoning passwords altogether in favor of passkeys,&#8221; Stewart wrote in the post. &#8220;Unfortunately, we live in the real world and passkeys will be inevitably lost due to device loss\/reset. As a partial solution, passkeys can be managed by a password manager, which offers greater resilience against loss, and yet the tradeoff is that the security of the password manager vault, itself, is now dependent on a master password and a second secret code at best.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, when his team contacted some of the affected vendors, they appreciated the information, he says \u2014 but there remains some exasperation with how difficult it is to level up on authentication methods in the consumer realm. For now, it feels as though their hands are tied.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Everybody&#8217;s always thinking well, you know, we know this person&#8217;s going to get locked out at some point, they&#8217;re going to lose their security key, and so we&#8217;re going to have to provide all these backup authentication methods, and unfortunately, that plays right back into the hands of the people running the phishing kits,&#8221; he says. &#8220;There&#8217;s a sense that consumers don&#8217;t really understand passkeys.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That&#8217;s not to say there aren&#8217;t options for better implementations, which Stewart says he wants to proselytize \u2014 especially when it comes to magic links for account recovery, which are &#8220;probably the most secure method,&#8221; Stewart says. &#8220;Magic links&#8221; are sent to an email account and will take users to a new login window to sign in.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If you click on a link sent to you in email and it opens up a completely new window, then that is a direct connection from you to the real site; you&#8217;re bypassing the phishing window, it breaks you out of this hijacked session,&#8221; he says. &#8220;And then you can go through the process of securely authenticating with a passkey in case it was redacted in a compromised session.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The one caveat is that this method is only as secure as an email inbox or the SMS network, which are common targets for attackers as well. For that reason, Stewart advocates using extra security layers, such as making sure these are auto-generated one-time links with short timeouts, and that logins are permitted from previously authenticated IP addresses only.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s also possible to implement &#8220;ward links,&#8221; which are like magic links but also require security questions or backup code entry to use, Stewart says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On a positive note, some of the providers the team talked to were open to considering such new approaches to thwart AiTM attacks, he adds.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"How Enterprises Can Prevent Compromise From Passkey Redaction\">How Enterprises Can Prevent Compromise From Passkey Redaction<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Beyond the obvious (using hardware-based keys and requiring fallback passwords to be complex and unique per website), security teams within organizations have a few options for shoring up defenses against forced authentication downgrades, Stewart notes, including using the aforementioned magic and ward links.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For instance, Microsoft&#8217;s Entra ID (formerly known as Azure AD) and Intune products allow admins to configure conditional access policies that can prevent proxied logins from succeeding, such as enforcing device login from \u201cdomain-joined, policy-compliant, managed devices\u201d only.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Verifying that you&#8217;re on a domain-joined machine and you can&#8217;t log into any of these services unless you have the permissions to makes it a lot harder for somebody to just take the credentials and run with them,&#8221; Stewart explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Also, many identity and access management (IAM) solutions for enterprises allow admins to define the login and account recovery flow for the organization, groups, or individual users, so &#8220;it may be possible to define a secure, passwordless login flow using passkeys, that isn\u2019t vulnerable to authentication method redaction attacks,&#8221; Stewart says, citing the open source Keycloak IAM software as one platform with that capability.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In general, security teams should assume every login session is AitM-compromised and work to ensure that any attempt to downgrade the authentication method, away from passkeys, must &#8220;break out&#8221; of the existing session before continuing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And finally, &#8220;encourage or require users to add multiple passkeys, so that losing one doesn&#8217;t block access to the account or require a fallback to less-secure authentication methods,&#8221; Stewart advised in his blog post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold ContentText-BodyTextChunk_italic\">Don&#8217;t miss the latest <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link ContentText-BodyTextChunk_bold ContentText-BodyTextChunk_italic\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/podcasts\" rel=\"noopener\">Dark Reading Confidential podcast<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">, where we talk to two ransomware negotiators about how they interact with cybercriminals: including how they brokered a deal to restore operations in a hospital NICU where lives were at stake; and how they helped a church, where the attackers themselves &#8220;got a little religion.&#8221; <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link ContentText-BodyTextChunk_bold ContentText-BodyTextChunk_italic\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/meet-the-ransomware-negotiators\" rel=\"noopener\">Listen now!<\/a><\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/passkey-redaction-attacks-subvert-github-microsoft-authentication\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>While online accounts are increasingly protected by passkey technology, it<\/p>\n","protected":false},"author":12,"featured_media":4307,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4306","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?fit=1800%2C1012&ssl=1",1800,1012,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?fit=1800%2C1012&ssl=1",1800,1012,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/passkey-redaction-attacks-subvert-github-microsoft-authentication.jpg?fit=1800%2C1012&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4306","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4306"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4306\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4307"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4306"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4306"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}