Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m only deeply familiar with the U2F (legacy) protocol, and such devices don’t expose a key pair usable for this purpose. When you enroll, you need to communicate with the token.

But more generally, this is a protocol issue. You can’t enroll your Yubikey with your browser and then, later, have your browser enroll that key with a WebAuthn-using site. You have to put the key in your USB port at the time you enroll with a website. And you can’t do this if it’s in a safe.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: