https://caniuse.com/#search=webauthn
That's... actually not as bad as I was expecting it to be. If you're willing to limit your audience to modern browsers only, the only holdout is Safari; and on that score, what else is new.
W3C approves WebAuthn as the web standard for password-free logins
61–70 of 154 posts
Re: W3C approves WebAuthn as the web standard for password-free logins
#62So what happens if you lose one of those USB devices? Can you use multiple USB devices on the same site?
Re: W3C approves WebAuthn as the web standard for password-free logins
#63Re: W3C approves WebAuthn as the web standard for password-free logins
#64Earlier quoted context omitted.
In addition to being able to add multiple devices, there are recovery scenarios that would ostensibly fall outside of the scope of WebAuthn. A service using WebAuthn could give you a set of one time use high-entropy codes that can be printed and stored in a safe location. When you use those code to gain access to an account for which you have lost your token(s), you would of course get an e-mail letting you know that…
webauthn has to solve the problem, or the problem will still exist and will stop mass adoption.
Re: W3C approves WebAuthn as the web standard for password-free logins
#65So what happens if you lose one of those USB devices? Can you use multiple USB devices on the same site?
If you don't have that, printing out backup codes and storing them somewhere safe is probably the way to go.
Re: W3C approves WebAuthn as the web standard for password-free logins
#66So what happens if you lose one of those USB devices? Can you use multiple USB devices on the same site?
That will depend on the site. It's not a new problem to think about either. For instance, you can set up multiple MFA mechanisms on Google, and I believe you can set up multiple U2F devices for any given account. To this day you cannot set multiple MFA devices on an AWS account. No, enrolling multiple devices at the same time from the same screen does not count.
Re: W3C approves WebAuthn as the web standard for password-free logins
#67https://caniuse.com/#search=webauthn
That's... actually not as bad as I was expecting it to be. If you're willing to limit your audience to modern browsers only, the only holdout is Safari; and on that score, what else is new.
Feels like a total failure to launch that the spec doesn't recommend the use of browser accounts as credential providers. Every single major browser has an associated web account with it (Firefox Account, Google account, Microsoft account, Apple id, etc) and could trivially use those accounts as authentication providers.
Re: W3C approves WebAuthn as the web standard for password-free logins
#68Earlier quoted context omitted.
webauthn has to solve the problem, or the problem will still exist and will stop mass adoption.
Not necessarily, it just has to not preclude a de facto standard solution. And it doesn't. The scheme described by OP above sounds fairly sane without compromising the overall security of the system (in the way that e.g, password reset forms and security questions do).
Nobody will remember where those are.
They will likely download the pdf, store it in downloads, where it will be used by some Trojan to hijack their account, or they will lose it during a device switch or some dataloss event.
Telling people to store one time codes securely and reliably, for every single account they own, and telling them that will only work for the services that bothered to add that on to their implantation of the standard, works for techys, but not the overall populous.
Re: W3C approves WebAuthn as the web standard for password-free logins
#69The last time I saw 2fa and fido talked about on here, someone recommended a set of 2 keys, but they ones they recommended are now out of stock. Does anyone have a recommendation with the reason? Thanks. Edit: With the reason. Jeez, what a typo.
1. Feitian FIDO MultiPass
2. Feitian ePass FIDO NFC