-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
Closed
Labels
0. Needs triagePending check for reproducibility or if it fits our roadmapPending check for reproducibility or if it fits our roadmapbug
Description
Currently "User Verification" for FIDO2 is set to "Discouraged" (#21880), users are always able to use passwordless login without entering a PIN or the like.
It is also possible to use a FIDO2 key as a U2F device at the same time. Essentially it enables passwordless login by owning the key and knowing the username/email. That is avoidable on a personal level, but might be a risk on a larger deployment.
Disabling U2F as a second factor for passwordless logins would avoid the risk of owning a masterkey to an account.
Metadata
Metadata
Assignees
Labels
0. Needs triagePending check for reproducibility or if it fits our roadmapPending check for reproducibility or if it fits our roadmapbug