TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

WebAuthn, and Only WebAuthn

29 pointsby albertgoeswoofalmost 3 years ago

2 comments

woojoo666almost 3 years ago
It seems like if you are on Linux (no Windows Hello or apple Face ID/ touch ID), then your only option for WebAuthn is to buy a Yubikey. Some people (including me) don't want a usb key. I'd much rather use TOTP or to verify using an existing verified device (like how Signal or Matrix does it)
评论 #31500150 未加载
评论 #31501175 未加载
评论 #31500875 未加载
评论 #31504454 未加载
GekkePrutseralmost 3 years ago
Too bad that they still require a username&#x2F;password and only use webauthn as 2FA.<p>Why not go full passwordless, with a fido2 token + pincode? It&#x27;s more secure and you need the token anyway. No password to remember or for an adversary to guess. Even the account can be derived from the token. With Office 365 all I have to do is insert the token, enter the pin, touch it (to avoid remote control abuse) and I&#x27;m logged in.<p>Simple as taking money out of the ATM and just as secure.
评论 #31500498 未加载