TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Phishing-Resistant MFA for Apps Without WebAuthn-Support (Fido). Enjoy

2 pointsby treesgrowslowover 2 years ago

1 comment

treesgrowslowover 2 years ago
We developed FIDO MFA via Standard Browser for applications without WebAuthn Support.<p>Only if we enforce FIDO-only MFA and block legacy authentication via SMS, Call and Authenticator App we are truly phishing-resistant.<p>WebAuthn is a requirement, but not always available. Some legacy Apps use WebViews without Webauthn support.<p>Detached FIDO Authentication is the answer.<p>We are looking forward to your feedback and hopefully improvement ideas.