Biometrics Support? #118
Replies: 1 comment
-
|
Hi! Thanks for participating! I would like to eventually support releasing passkeys created with the platform authenticator using biometrics. I have not considered exactly how we should accomplish that. These two articles summarize the security considerations: "On-device WebAuthn and What Makes It Hard To Do Well" and "Why does Gnome Fingerprint Unlock Not Unlock the Keyring?". In short, there's no secure way to associate a fingerprint match with a secret if you don't trust the OS. Now, our threat model excludes Some things I would want from the fprintd response though:
PAM and Polkit can be used to achieve user verification generally, but if we decide to have a separate device PIN for user credentials, then we wouldn't be able to use PAM (or Polkit?), as I don't think it gives you back information about which authentication method was exercised.1 Windows Hello does this, but macOS does not (you either use biometrics or account password for UV), so we have a decision to make. Once the decision about PINs is made, then we can determine what to do with biometrics. Footnotes
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello, I stumbled upon this project recently when learning about WebAuthn/FIDO2. I like what this project aims to do and I might even be interested in contributing sometime.
One thing I was curious about is whether biometrics (I'm mainly interested in fingerprint readers) is something this project will support. Fingerprint readers in particular are brokered by
fprintd, and I wonder if an integration with this DBus service has been considered.If these plans do exist, please consider documenting them. I was not able to find them, though maybe I was too hasty.
Beta Was this translation helpful? Give feedback.
All reactions