2factorauth / passkeys

FIDO2 Passkey directory
https://passkeys.2fa.directory
Creative Commons Attribution 4.0 International
17 stars 9 forks source link

Update British Airways #33

Closed pmcarrion closed 2 weeks ago

pmcarrion commented 3 weeks ago

Site name

British Airways

Site URL

https://www.ba.com

Update reason

It now supports passkey authentication.

Additional information

No response

Issue Eligibility

Carlgo11 commented 3 weeks ago

Thanks for the pull request @pmcarrion! I see that you haven't added any documentation link. Could you find one that describes how to enable 2FA on the site?

If no documentation is available or you can't find it, please attach screenshots of the 2FA setup and/or login process.

Note Remember to blur or crop out any personal information linked to you.

You can attach the screenshots here in a comment like this: screenshot

pmcarrion commented 3 weeks ago

These are the steps to create a passkey on BA: 1) Go to Combine your Avios 2) Choose Qatar or Finnair 3) Log in to link accounts 4) 2FA passkey creation prompt shows up.

The same steps apply to create passkeys for Iberia and Vueling.

Carlgo11 commented 3 weeks ago

So it is Qatar or Finnair that offer Passkey support?

pmcarrion commented 3 weeks ago

No, just BA. Linking from BA to QR or FI activates the Passkey generation site. But it doesn't work the other way around.

This is confirmed on the Qatar website:

(a) BAEC uses Multi Factor Authentication (MFA) as an additional layer of security at login to ensure operation in line with GDPR regulations and best practices for account security.

(b) Privilege Club uses One Time Passwords (OTP) as an additional layer of security operation in line with GDPR regulations and best practices for account security.

(c) In some circumstances, the Member (or Linked Member as the case may be) will be required to complete both the British Airways MFA and Qatar Airways OTP during Avios transactions such as account linking, movement of Avios and redemption of Avios.

Carlgo11 commented 2 weeks ago

Resolved in 2factorauth/twofactorauth#8236