3 ms·
Yes, to set a PIN protecting the non-discoverable credentials. The FIDO PIN can be changed while you have access to the authenticator and not to the credentials
by Borealid 2y ago
Yes, to set a PIN protecting the non-discoverable credentials. The FIDO PIN can be changed while you have access to the authenticator and not to the credentials it previously created.
- arianvanp 2y agoUser verification is optional. If you only do user presence and non-discoverable, then WebAuthn is completely stateless and deterministic for a given (challenge,rpId,origin) triplet
- michaelt 2y agoIsn't a 'passkey' with no discoverable credentials and no user verification just a regular U2F token?