Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
@BjornW@mastodon.social
@BjornW@mastodon.social
@BjornW@mastodon.social  路  activity timestamp 2 weeks ago

Sounds doable. Oh snag! The interface does not allow me to pick a passkey like the Help sections show.

Apparently Passkeys are not supported anymore!?

I have quit a high-tolerance for bureaucracy, opaque rules & stupid systems, but I'm not going to waste anymore time on this for now. I just wanted to discuss a possible bug 馃槱

Please @EC_OSPO @EC_DIGIT or whoever, fix this horrible system & enable participation by the wider opensource community.

CC @bert_hubert @rriemann

#OpenSource #Tech

Benedikt Wi
Benedikt Wi
@benedikt@ruhr.social replied  路  activity timestamp last week

@BjornW @EC_OSPO @EC_DIGIT @bert_hubert @rriemann After login in with a password, I was able to setup a #nitrokey at https://ecas.ec.europa.eu/cas/userdata/webauthn/manageMyWebAuthnDevices.cgi (if you prefer some software solution: #bitwarden / #vaultwarden also works) #webauthn #passkey

EU Login

  • Copy link
  • Flag this comment
  • Block
Daniel Appelquist boosted
W3C Developers
W3C Developers
@w3cdevs@w3c.social  路  activity timestamp 4 weeks ago

Web Authentication defines an #API for creating and using securely and smoothly public key-based credentials in Web #browsers.
This 3rd level adds client features that make passkeys easier to use and help transition from passwords via conditional mediation (learn more at https://passkeys.dev). It also enables cross-origin iframe support for use cases like federated identity and payments #WebAuthn

鈻讹笍 https://www.w3.org/TR/webauthn-3 #timetoimplement

Feedback wlc: https://github.com/w3c/webauthn/issues

WebAuthn
WebAuthn
WebAuthn

Web Authentication: An API for accessing Public Key Credentials - Level 3

  • Copy link
  • Flag this post
  • Block
W3C Developers
W3C Developers
@w3cdevs@w3c.social  路  activity timestamp 4 weeks ago

Web Authentication defines an #API for creating and using securely and smoothly public key-based credentials in Web #browsers.
This 3rd level adds client features that make passkeys easier to use and help transition from passwords via conditional mediation (learn more at https://passkeys.dev). It also enables cross-origin iframe support for use cases like federated identity and payments #WebAuthn

鈻讹笍 https://www.w3.org/TR/webauthn-3 #timetoimplement

Feedback wlc: https://github.com/w3c/webauthn/issues

WebAuthn
WebAuthn
WebAuthn

Web Authentication: An API for accessing Public Key Credentials - Level 3

  • Copy link
  • Flag this post
  • Block
hexa-
hexa-
@hexa@chaos.social  路  activity timestamp 2 months ago

#Gandi just "upgraded" me from U2F to E-Mail MFA.

U2F binding was removed. E-Mail MFA was put in place instead.

No advanced warning, no migration period.

Would have gladly upgraded that to #Webauthn had they asked.

Strong signal that the "no bullshit" policy is no more.

E-Mail from Gandi Support:

Dear user,

Gandi is evolving, and so is its security!

Security keys now use a new protocol. Keys registered before September
10, 2019, are no longer compatible and have been deactivated.

Therefore, we have removed your security keys: yubikey from your account.

To maintain a satisfactory level of security, we have enabled MFA via email
for your account.

However, you can re-register them in your administration console, in the
ACCOUNT application.

Please feel free to contact us if needed.

Sincerely,
The Gandi Team
E-Mail from Gandi Support: Dear user, Gandi is evolving, and so is its security! Security keys now use a new protocol. Keys registered before September 10, 2019, are no longer compatible and have been deactivated. Therefore, we have removed your security keys: yubikey from your account. To maintain a satisfactory level of security, we have enabled MFA via email for your account. However, you can re-register them in your administration console, in the ACCOUNT application. Please feel free to contact us if needed. Sincerely, The Gandi Team
E-Mail from Gandi Support: Dear user, Gandi is evolving, and so is its security! Security keys now use a new protocol. Keys registered before September 10, 2019, are no longer compatible and have been deactivated. Therefore, we have removed your security keys: yubikey from your account. To maintain a satisfactory level of security, we have enabled MFA via email for your account. However, you can re-register them in your administration console, in the ACCOUNT application. Please feel free to contact us if needed. Sincerely, The Gandi Team
  • Copy link
  • Flag this post
  • Block
Lucas Garron boosted
Matthew Miller :donor:
Matthew Miller :donor:
@iamkale@infosec.exchange  路  activity timestamp 5 months ago

The FIDO Alliance put out an official statement in response to recent security research reports and conference talks that misrepresent endpoint compromise as "passkey vulnerabilities" 馃敟

https://fidoalliance.org/passkeys-are-not-broken-the-conversation-about-them-often-is/

#passkeys #webauthn

  • Copy link
  • Flag this post
  • Block
Matthew Miller :donor:
Matthew Miller :donor:
@iamkale@infosec.exchange  路  activity timestamp 5 months ago

The FIDO Alliance put out an official statement in response to recent security research reports and conference talks that misrepresent endpoint compromise as "passkey vulnerabilities" 馃敟

https://fidoalliance.org/passkeys-are-not-broken-the-conversation-about-them-often-is/

#passkeys #webauthn

  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.2-alpha.22 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct