nthdimtech / signet-client

Client code for Signet and Signet HC
https://www.nthdimtech.com/signet
GNU General Public License v3.0
19 stars 8 forks source link

Github forgets SignetHC as a two-factor authentication key after power-off. #164

Open lundacode opened 3 years ago

lundacode commented 3 years ago

Two-factor authentication with SignetHC as a security key works but only as long as SignetHC is not restarted.

How to reproduce: Plug in SugnetHC, log in to a github account. Press "Use security key" button. Long press blinking button on SignetHC. Observer brief "Success!" notification then the final red "Security key authentication failed." label.

Client version 0.9.17.1 Firmware version: 0.2.2

This is not a bug with gmail.com, only(?) with github.com.

dumblob commented 2 years ago

Is this still a valid issue?

If so, does it affect also the original Signet (not SignetHC)?

Btw. does Signet support WebAuth?

I'm asking these questions as GitHub recently decided to force every single contributor to use 2-factor authentization. If Signet(HC) worked well for GitHub 2FA (TFA) that could be a major boost in sales for you @nthdimtech and a reason to update the design to use available electronic components.

lundacode commented 2 years ago

Yes, it appears valid. I can 2FA with google but not with github.

No Idea, I have no old Signet.

I don't know about WebAuthn, probably not supported, I don't remember seeing it.