Closed Woolworths closed 1 year ago
We follow the hey.com flow, they use TOTP, recovery codes, and security keys as 2FA, also it is good for the generator because it works in an incremental way...
Sure, just wanted to throw this possibility out there. As passkeys (WebAuthn) gains ground, it will start being used as a primary method of authentication.
I believe this is worth re-evaluating with the recent spike in popularity and adoption of passkeys/webauthn
I would also like to see this become an option, Passkeys are becoming popular because of the wide adoption lately (e.g. by Google, Shopify, Amazon, etc.)
Right now, WebAuthn support is used as secondary authentication (in 2FA). This issue tracks using WebAuthn as a primary method of authentication.
Perhaps, for now it's not the best time because support is still increasing. But maybe it would be a good idea to have it alongside a password? Or make it work similar to how OAuth works (e.g. "Sign In With Passkeys")?