March 26Mar 26 Any plans for Enpass to support FIDO2?Why:A site I use offers security via Passkey but not TOTP security. A search returned this interesting info:"Q: Does Enpass TOTP meet <site> FIDO2 certification standard for secure authentication?A: No, Enpass TOTP does not meet <site> FIDO2 certification standard for secure authentication. Enpass TOTP generates Time-Based One-Time Passwords (TOTP), which are explicitly described as not recommended for modern, high-security authentication because they are susceptible to phishing, replay attacks, and malware interception. <site> and other major ... institutions require phishing-resistant methods, such as FIDO2 security keys (hardware tokens) or Passkeys, which cryptographically bind authentication to the specific domain and cannot be intercepted by phishing sites. FIDO2 standards (WebAuthn) use asymmetric cryptography where the secret never leaves the device, whereas TOTP relies on a shared secret that can be compromised if the server is breached or if the user is tricked into entering the code on a fake site. While some hardware tokens can support both TOTP and FIDO2 functions, the TOTP feature itself on any device (including Enpass) does not provide the phishing resistance required by FIDO2 standards or recommended by the U.S. government for federal agencies.Android phones running version 7.0 or higher can function as a FIDO2 security key for Google accounts, allowing users to log in on Windows, Chrome OS, or macOS devices without needing a separate physical token. This feature utilizes Bluetooth and Location data to verify that the phone is in the same location as the computer being used for sign-in, providing phishing-resistant two-factor authentication. "
Saturday at 03:51 PM2 days Enpass already has passkey support. When requested by a website, it generates one and the browser plugin asks you to store it.
Create an account or sign in to comment