Works fine, except for one thing
-
I like how it works, but I only give it 3 stars because of this:
When I first registered my keys, it allowed to access with no password and just with the key inserted and a non-biometric touch. No PIN, and no fingerprint was required to access, I guess that it just uses FIDO U2F standard by default.
This should never be allowed, at least by default. To solve it, I had to change, in the settings, “user verification”. This should be mandatory.
According to the owner, this is configured like that because mobile devices do not work with WebAuthn. I’d rather to allow always the possibility of using password + U2F than this option. U2F for passwordless authentication should NEVER be allowed.
If it is corrected, I would give 5 stars, because besides this it works fine.
- The topic ‘Works fine, except for one thing’ is closed to new replies.