Remix.run Logo
EvanAnderson 2 hours ago

I haven't used a FIDO2 token other than playing around with it on a Yubikey. There, at least, I have to have the PIN to unlock the Yubikey before I can use the FIDO2 credentials (if I'm remembering correctly).

Are there hardware token implementations where mere possession of the token is all that's necessary to use the passkeys stored on it? That's incredibly stupid, and should have been disallowed by the standard, if that's the case.

iamnothere 2 hours ago | parent | next [-]

Yes, the PIN is optional even on Yubikeys, although I think individual providers can require it. Ideally a strong PIN should be used but people may just reuse their ATM PIN, birthday, etc.

EvanAnderson 37 minutes ago | parent [-]

I didn't realize PIN was optional.

See my other comment re: the IT industry being fools.

UltraSane an hour ago | parent | prev [-]

That is how almost all standard FIDO2 tokens work. You just have to press the capacitive sensor when prompted. You can get fancier biometric tokens that require a fingerprint.

EvanAnderson 38 minutes ago | parent [-]

That's the stupidest thing ever.

All this hullabaloo taking away user freedom to export keys and backup tokens but physical possession is all that's necessary to use it by default.

We are a ship of fools, the IT industry.