3 ms·
I use Okta and it supports webauthn/fido just fine, seemingly by default, including touch id (or any standard USB key). If it does not, it's because your SSO ad
by ev1 4y ago
I use Okta and it supports webauthn/fido just fine, seemingly by default, including touch id (or any standard USB key). If it does not, it's because your SSO administrator is intentionally turning it off.
Okta does not have my phone number or an app installed. I do not ever want to be pushed an approval, because I don't know who or what triggered it. I only want to proactively authenticate.
- eropple 4y agoOh, hey, I totally didn't even think of that. Of course a Yubikey (or whatever) would work there, too. Looks like Duo will work with FIDO2, too.
- ev1 4y agoYeah, pretty much. I explicitly want 2FA with a real 2FA factor on all of my services and all of my machines, but my caveat is that it has to be in my custody - yubikey, totp (not ideal but I do hold an encrypted back up of my seeds that I physically refresh sometimes), fido2, smart card, etc. Push no. Push on a personal device even more no. SMS and phone absolutely FUCK NO for any reason.