3 ms·
Thanks for the info. This is not really 2FA anymore though, is it? Now WebAuthn authentication is happening on the same device as the one I'm using to log into
by trulyrandom 7y ago
Thanks for the info. This is not really 2FA anymore though, is it? Now WebAuthn authentication is happening on the same device as the one I'm using to log into the service. Is there a way to use my phone as a completely separate factor for WebAuthn authentication?
- arianvanp 7y agoWebauthn is not a 2fa API. It's an authentication API. One of its usecases is to enhance password login (2fa) but can also be used as a single factor. That is up to the implementor. The implementor can ask the browser for certain security features of the authentication device. E.g. is the authentication device the same device as where the authentication flow is happening; is there a biometric check on the device or a pin on the device (i.e. the second factor is there but device-local) who is the manufacturer of the device (with consent of the user; given this is privacy-sensirive info) etc. And the implementor can then make a decision whether a device is 'strong' enough for single factor auth. All this information is cryptographically attested by the device. You can ignore all that and only use it as a second factor always though. That's totally up to you and how you use the authentication primitives that webauthn provides.
- trulyrandom 7y agoThanks again for the info. Sounds like I have some more reading up to do on WebAuthn.