FIDO U2F as a second factor in the customer menu
Summary
Manuel Schmitt adds FIDO U2F to the customer menu and thereby supports physical as well as virtual security keys. FIDO U2F was offered in addition to SMS and OATH-TOTP. The web hosting management itself had not yet been switched over at the time of publication.
Ideas
- Hardware-backed factors resist phishing better than reusable one-time codes.
- A customer portal can offer several methods without immediately rebuilding every target system.
- Biometric devices can act as virtual security keys without sending biometric data to the service.
Insights
- Strong authentication is first useful at a service’s administrative control points.
- A gradual rollout is justifiable if the remaining protection gaps stay visible.
Facts
- Physical and virtual U2F-compatible security keys are supported.
Recommendations
- Register at least two independent security keys.
- Document recovery and revocation of lost factors.
References
Read the original article on Hostblogger
Links to the original source and the Web Archive open in a new tab.