Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"Passwordless" Demo is misleading #353

Open
Aptimex opened this issue Feb 6, 2021 · 0 comments
Open

"Passwordless" Demo is misleading #353

Aptimex opened this issue Feb 6, 2021 · 0 comments

Comments

@Aptimex
Copy link

Aptimex commented Feb 6, 2021

Demo.yubico.com allows you to register a hardware security key (using WebAuthn) as either a second factor (default), or using a resident credential for logging in without needing a password OR username. But the second option (when selecting "Add Security Key) is described by a checkbox that says "Enable passwordless login with this key."

This is misleading because "passwordless" WebAuthn usually refers to using the exact same (non-resident) WebAuthn protocol as MFA registration, but the security key completely replaces the password (and instead requires local user verification, i.e. PIN). The "passwordless" option on the demo site would more accurately be described as "usernameless." The website should be changed to reflect that difference, and perhaps a third more accurate "passwordless" option implemented. It would also be good to specify there that the "usernameless" option will take up limited space on the security key, unlike the other two options.

Good example of another site that correctly demonstrates this difference here (no affiliation): https://www.passwordless.dev/passwordless

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant