Adding a passkey makes it mandatory as MFA on other devices

(#1377) Feature Shipped security

Thread

Comment by Hampus
HampusStaff 1 vote originally by @hampus-fluxer on GitHub 1 reply
This is not a bug report but is a feature request to potentially allow instances to configure whether WebAuthn is a two-factor authentication method or not. Fluxer has made the decision, like Discord, that WebAuthn is a two-factor authentication method, and it is implemented as such. If it weren't required to login to your account, but you could just use an email and password, it is not two-factor authentication and it provides zero extra security. It only provides convenience. That may be a valid way someone wants their instance to work, however, and it is worth discussing as a feature request.
Comment by @Victor-root
RexSystem 1 vote originally by @Victor-root on GitHub OP
I understand that WebAuthn is intentionally treated as MFA. The problem I'm pointing out is that this can completely block login on another device if the registered passkey is device-bound. Example:
  • PC A: account has a locally stored passkey
  • PC B: that passkey is not available
  • TOTP is disabled
  • I enter the correct email and password on PC B
  • Fluxer then requires the passkey from PC A, so I cannot log in at all
So this is not just about convenience. Registering a device-bound passkey on one machine can make the account inaccessible from another machine unless the user has already configured another MFA method.