Adding a passkey makes it mandatory as MFA on other devices

(#1377) Feature Shipped security

Thread

Comment by Hampus
HampusStaff 1 vote originally by @hampus-fluxer on GitHub 1 reply
This is not a bug report but is a feature request to potentially allow instances to configure whether WebAuthn is a two-factor authentication method or not. Fluxer has made the decision, like Discord, that WebAuthn is a two-factor authentication method, and it is implemented as such. If it weren't required to login to your account, but you could just use an email and password, it is not two-factor authentication and it provides zero extra security. It only provides convenience. That may be a valid way someone wants their instance to work, however, and it is worth discussing as a feature request.
Comment by @Artimba
RexSystem 1 vote originally by @Artimba on GitHub
I get the confusion here. I am an avid passkey user (between a yubikey and bitwarden), and see why having 2FA disabled would lead to the belief that the passkey is just an alt auth method. Bitwarden passkey's offer a convenience to many platforms, while my yubikey is a security device. With more password managers adding support for them, I see this becoming a more common frustration. The ability to add a passkey while 2FA is disabled is strange if the intended behavior is that passkeys MUST be 2FA. I would imagine adding a passkey immediately toggles on 2FA and disables the button in that case (or pops up a modal warning the user about the passkey when trying to disable 2FA with one). Also its sad hearing that passkeys are considered bad UX. I thought they were one of the greatest things to happen with password managers.