11 ms·
Firefox enables deprecated Fido U2F Support for Google Accounts
- drewg123 8y agoNot a web dev. Is there a way to force U2F with firefox for google accounts? The lack of (obvious) U2F support in FF for Google accounts is one of the things holding me back from switching back to FF from Chrome.
- web007 8y ago"We agreed then to implement a hard-coded permission for Google Accounts when utilizing FIDO U2F API credential support, whether that was via Web Authentication’s backward compatibility extension, or via Firefox’s FIDO U2F API support hidden behind the “security.webauth.u2f” preference." Directly, https://support.yubico.com/support/solutions/articles/15000017511-enabling-u2f-support-in-mozilla-firefox https://support.yubico.com/support/solutions/articles/150000...
- ecesena 8y agoNote that if you enable 2fa with Chrome, then you can log in with Firefox. Just adding/removing keys (in Google) doesn't work.
- chedabob 8y agoYep, I've just been through this process on both personal and work Gsuite. They've changed the message in Firefox to make it a little clearer this is how to do it.
- mediocrejoker 8y agoThis is good. It's been working with FastMail for months so I'm not sure what the problem was.
- lkbm 8y agoFrom what I understand: * FastMail has implemented WebAuth, the newer standard, which Firefox supports * Google hasn't implemented WebAuth because they have to(?) wait for the end-of-life of old Android devices. * Firefox is going to put an override so that you can use the old standard on Google accounts, which Google does support. It sounds like Google's slowness to enable WebAuth is a somewhat legitimate issue of backwards compatibility for old devices, though I haven't personally evaluated it.
- tgragnato 8y agoAndroid devices do not receive updates. This creates all sort of issues, including inconsistency and lack of features. Legitimate and sensible decision, but sad.
- chrismorgan 8y agoFastMail is still using the old FIDO U2F API; we’ve been planning on migrating to WebAuthn since it was finalised, but investigation revealed that the migration would not be entirely straightforward (especially if tokens registered with WebAuthn needed to still work with U2F, which at the time was important but could probably now be skipped), so we deferred it, since the U2F support is adequate for most users. I expect this is the experience with many small teams that support the FIDO U2F API. Documentation on migration is difficult to come by; I think https://www.imperialviolet.org/2018/03/27/webauthn.html https://www.imperialviolet.org/2018/03/27/webauthn.html is the main source I’ve encountered.
- lkbm 8y agoThanks for the clarification.
- AdmiralAsshat 8y agoWould be nice. Even with the experimental settings turned on in about:config, I could only read input from my Yubikey, I couldn't add one. I had to install Chromium just so I could add my Yubikey to my Google account.
- lurker213 8y agoif you are on linux and using the flatpak version of firefox it could be because of sandboxing and USB read permissions.
- ecesena 8y agoI think this is because of Google - they only allow registration via Chrome (to the best of my knowledge). But then you should be able to use your key from Firefox.
- akerl_ 8y agoThis is mentioned as a side note in the first comment of the Firefox issue: they were explicitly whitelisting the “Sign” operation so that registration didn’t work.
- snek 8y agoDamn shame to see the internet move backwards because Google refuses to use the standardized APIs. Edit: Usually HN is so angry about Google not following web standards but everyone in this thread seems to be in favor of Google trampling the WebAuthn standard. Weird.
- jrockway 8y agoWhat sites could you sign into with a cryptographic second factor before Google launched U2F? All that was out there were easily-phishable TOTP tokens. Now you can register a security key and use it as a second factor on desktops and phones. It's pretty impressive, though unfortunate that ultimately the industry picked a similar-but-different standard. What sites currently let me authenticate with WebAuthn? (Github still uses U2F, it seems.)
- phren0logy 8y agoDropbox uses WebAuthn. They are, as far as I can tell, the most significant site using it currently.
- ecesena 8y agoMicrosoft also supports passwordless login, the "novelty" of FIDO2. I just found it out yesterday reading this article [1], page 3 (it's in German). Disclaimer: I make the Solo key that's mentioned in the article. [1] https://www.golem.de/news/fido-sticks-im-test-endlich-schlechte-passwoerter-1903-139953-3.html https://www.golem.de/news/fido-sticks-im-test-endlich-schlec...
- will4274 8y ago> What sites currently let me authenticate with WebAuthn? Microsoft sites like Outlook and OneDrive.
- agwa 8y ago> What sites currently let me authenticate with WebAuthn? (Github still uses U2F, it seems.) https://login.gov https://login.gov
- inetknght 8y agoDoes this mean I can finally use my Yubikey in Firefox on Linux as my second factor authentication with my Google accounts?
- ecesena 8y agoPretty sure you can already use it. You can't register it currently.
- taeric 8y agoI can confirm this. I'm also curious if anyone in this topic has advice for how to make U2F a habit. I posted https://news.ycombinator.com/item?id=19316509 https://news.ycombinator.com/item?id=19316509, but didn't get anything. :(
- deleted 8y ago[deleted]
- bpye 8y agoI've found the Firefox U2F support on Windows, especially with Google, quite temperamental. It will prompt me to touch my Yubikey and I will, only to get some failure. I can't work out what causes it but replygging and retrying a few times normally gets me logged in. Very irritating.
- inetknght 8y agoNo problem: I already registered it using Chrome on a different computer. Nonetheless, I consistently have trouble using it on Firefox on Linux.
- caprese 8y agoDoes this make Ledger Nanos work on Firefox now?
- amluto 8y agoIf you’re on Linux, you’ll want u2f-hideaway-policy installed to avoid permission issues. https://github.com/amluto/u2f-hidraw-policy https://github.com/amluto/u2f-hidraw-policy
- taeric 8y agoIs this necessary for newer installs? Pretty sure the titan keys and the yubikey I have worked without any special setup on the latest ubuntu.
- amluto 8y agoAFAICT Ubuntu uses a big hack that maintains a list of known U2F tokens rather than detecting whether the device speaks the U2F protocol. u2f-hidraw-policy does the latter, so it’s forward compatible. I should get it into upstream systemd.
- breakingcups 8y agoFor all the hooks Google has into nearly every Android device through Google Play, I would've thought the one party burned in ROMs wouldn't be a problem for would be Google.