Skip to content

Will it have Challenge-Response for Apps like LUKS or KeePassXC? #23

Answered by nickray
JannF asked this question in Q&A
Discussion options

You must be logged in to vote

We still think the way to do this is to use the hmac-secret extension that is part of the actual standard (it is in essence HMAC-SHA256 challenge-response). In that sense, the answer is, yes, at launch (and Solo V1 has it too, just like every fully certified FIDO2 dongle).

If the question is whether we will implement Yubico's proprietary app (in essence, HMAC-SHA1 challenge-response), the answer is no, we do not plan to do so. This sentiment is shared by other vendors such as Trezor - if OSS such as KeePassXC and LUKS moves on to an actual standard instead of one company's private sauce, everyone wins.

For LUKS, I know of https://github.com/shimunn/fido2luks, for password managers (also B…

Replies: 1 comment 11 replies

Comment options

You must be logged in to vote
11 replies
@tmthrgd
Comment options

@My1
Comment options

@My1
Comment options

@nickray
Comment options

@My1
Comment options

Answer selected by conorpp
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
5 participants