Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Firefox lets you enable software tokens, and disable USB tokens: in about:config, set

    security.webauth.webauthn_enable_softtoken=true
    security.webauth.webauthn_enable_usbtoken=false
then the registration will go through without needing a hardware token.


Err... and how is my software token generated? Where is it stored? Can I move it around browsers, e.g. use it with my Mobile Firefox after I generated in on the desktop?


In other words, I can't use it in production (yet), because I'd need to ask users to change browser settings for it to work. That's disappointing :(


You can use it in production for users who have hardware tokens (and it is used in production by many sites for 2FA). But if you mean you can't _exclusively_ use it in production, then yes that is probably true since not all users will have authenticators (yet).


It’s almost like the designers thought - we are so damn close to killing the password, but, nah, why bother.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: