4 ms·
One interesting effect of Twitter’s onion address: your 2FA options are limited. Any WebAuthn/FIDO/U2F keys you have registered with your Twitter account won’t
by anjbe 5y ago
One interesting effect of Twitter’s onion address: your 2FA options are limited. Any WebAuthn/FIDO/U2F keys you have registered with your Twitter account won’t work, because the key registration is tied to the domain name. I have the same problem on Facebook. I can only use these onion sites if I log in with TOTP.
One would think you could re‐register the keys while logged in to the onion site, but I’ve never succeeded with this on Facebook or Twitter. I don’t know if there is a technical limitation preventing WebAuthn from being used over onion sites, or just a problem with these particular sites’ implementations. Tor itself is not the problem—you can use a registered WebAuthn key over Tor if the domains you’re visiting are facebook.com or twitter.com.
- cyphar 5y agoAs you say, it's because WebAuthn is by design tied to the origin and onion sites are a different domain. There's been attempts to standardise a way to indicate that site XYZ.onion is actually the same as ABC.com through the Alt-Svc header but it seems unlikely that this would be used by something as security critical as WebAuthn. I suspect the reason you can't enroll the same key again is that Twitter doesn't know that you're accessing it from an onion address? Or it doesn't know how to register the same key twice with different domains? I agree it should be possible.