Skip to content

How to identify the FIDO2 devices consistently #622

Answered by nuno0529
EvgeneOskin asked this question in Q&A
Discussion options

You must be logged in to vote

https://w3c.github.io/webauthn/#sctn-privacy-attacks
IMHO, I don't think use serial numbers is a good approach if you are targeting FIDO2 devices.
And I will suggest to use AAGUID of getInfo's response for different models by using FIDO's MDS3 services or maintain a key-value map of them likes
https://support.yubico.com/hc/en-us/articles/360016648959-YubiKey-Hardware-FIDO2-AAGUIDs
https://github.com/opotonniee/fido-mds-explorer (just a quick link website, not formal website of FIDO MDS3)

Replies: 1 comment 7 replies

Comment options

You must be logged in to vote
7 replies
@EvgeneOskin
Comment options

@ntwerdochlib
Comment options

@LDVG
Comment options

@ntwerdochlib
Comment options

@LDVG
Comment options

Answer selected by martelletto
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
5 participants