Hacker News new | past | comments | ask | show | jobs | submit login

The site you're looking at offers a variety of different WebAuthn flows. I linked the one that behaves how you described, requiring a PIN (and yes it requires the PIN to log in) but now you've found and linked a different flow that doesn't require PINs and sure enough it doesn't require PINs.

I guess you could say the site is badly labelled. The true FIDO2 flow that I linked you to above is labelled usernameless rather than passwordless.

The flow they've called passwordless works with an ordinary FIDO key it doesn't need FIDO2. Because it simply doesn't have a password. Passwordless. Simple.




Trying it on Chrome, it works as you say. On Firefox it just failed to auth, I assumed it was because my Yubikey lacked onboard storage for storing the user details but it looks like it's because of the lack of PIN support. Thanks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: