Skip to content
View in the app

A better way to browse. Learn more.

Enpass Discussion Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Need FIDO2 Passkey because TOTP "...not recommended for modern, high-security authentication..."

Featured Replies

Any plans for Enpass to support FIDO2?

Why:

A site I use offers security via Passkey but not TOTP security. A search returned this interesting info:

"Q: Does Enpass TOTP meet <site> FIDO2 certification standard for secure authentication?

A: No, Enpass TOTP does not meet <site> FIDO2 certification standard for secure authentication.

Enpass TOTP generates Time-Based One-Time Passwords (TOTP), which are explicitly described as not recommended for modern, high-security authentication because they are susceptible to phishing, replay attacks, and malware interception.

<site> and other major ... institutions require phishing-resistant methods, such as FIDO2 security keys (hardware tokens) or Passkeys, which cryptographically bind authentication to the specific domain and cannot be intercepted by phishing sites.

FIDO2 standards (WebAuthn) use asymmetric cryptography where the secret never leaves the device, whereas TOTP relies on a shared secret that can be compromised if the server is breached or if the user is tricked into entering the code on a fake site.

While some hardware tokens can support both TOTP and FIDO2 functions, the TOTP feature itself on any device (including Enpass) does not provide the phishing resistance required by FIDO2 standards or recommended by the U.S. government for federal agencies.

Android phones running version 7.0 or higher can function as a FIDO2 security key for Google accounts, allowing users to log in on Windows, Chrome OS, or macOS devices without needing a separate physical token. This feature utilizes Bluetooth and Location data to verify that the phone is in the same location as the computer being used for sign-in, providing phishing-resistant two-factor authentication. "

  • 5 weeks later...

Enpass already has passkey support. When requested by a website, it generates one and the browser plugin asks you to store it.

  • Author

Thanks! Missed the announcement. I'll look for use details.

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.