Skip to content

How to identify the FIDO2 devices consistently #622

Answered by nuno0529
EvgeneOskin asked this question in Q&A
Discussion options

You must be logged in to vote

https://w3c.github.io/webauthn/#sctn-privacy-attacks
IMHO, I don't think use serial numbers is a good approach if you are targeting FIDO2 devices.
And I will suggest to use AAGUID of getInfo's response for different models by using FIDO's MDS3 services or maintain a key-value map of them likes
https://support.yubico.com/hc/en-us/articles/360016648959-YubiKey-Hardware-FIDO2-AAGUIDs
https://github.com/opotonniee/fido-mds-explorer (just a quick link website, not formal website of FIDO MDS3)

Replies: 1 comment 7 replies

Comment options

You must be logged in to vote
7 replies
@EvgeneOskin
Comment options

@ntwerdochlib
Comment options

@LDVG
Comment options

LDVG Sep 18, 2023
Maintainer

@ntwerdochlib
Comment options

@LDVG
Comment options

LDVG Sep 19, 2023
Maintainer

Answer selected by martelletto
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
5 participants