Re: Fido2 sometimes prompts for PIN

[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

 



On Thu, Aug 25, 2022, at 8:34 AM, Jeremy Hansen wrote:
> Yubikey BIO.
>
> I’m noticing it consistently prompts me for pin when I use a different 
> fingerprint, so I guess what seemed to be a random prompt for my PIN is 
> just me not touching the key properly. This also explains why it 
> prompts for a touch the section time. I’d like to always prompt for PIN.
>
> I also noticed if I use the wrong fingerprint, as long as my PIN is 
> correct, it allows me to proceed. I guess I expected that a second bad 
> fingerprint after the PIN prompt would kick me out.

I am afraid that is by design. Fingerprint verification and PIN authentication are codified as equivalent forms of user verification in FIDO2. They satisfy the same criteria from the verifier's perspective, and there is no way for the verifier to know which method was used.

(Apologies in advance if the formatting of this message is skewed; I am typing it from a browser.)

-p.
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev




[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux