Skip to content

Disable U2F 2FA for Webauthn passwordless logins #22982

@soxhi8

Description

@soxhi8

Currently "User Verification" for FIDO2 is set to "Discouraged" (#21880), users are always able to use passwordless login without entering a PIN or the like.
It is also possible to use a FIDO2 key as a U2F device at the same time. Essentially it enables passwordless login by owning the key and knowing the username/email. That is avoidable on a personal level, but might be a risk on a larger deployment.

Disabling U2F as a second factor for passwordless logins would avoid the risk of owning a masterkey to an account.

Metadata

Metadata

Assignees

No one assigned

    Labels

    0. Needs triagePending check for reproducibility or if it fits our roadmapbug

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions