Ask HN: WebAuthn – Replace Password or Second Factor?

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • WebAuthn

    A simple PHP WebAuthn (FIDO2/Passkey) server library (by lbuchs)

  • webauthn

    Web Authentication: An API for accessing Public Key Credentials

  • As usual - it depends.

    There have been two main problems with WebAuthn as a primary factor. The first is that the UX experience of WebAuthn as a primary factor - either for "passwordless" or "usernameless" scenarios - has been pretty rough. The WebAuthn W3C group has put together a document that goes into far more detail [1]. One of the items out of that discussion was a standards change [2] that was merged in a few months ago. Now it's up to browser vendors to implement that change over the coming months and years.

    The second problem with WebAuthn is that device based authentication has been historically risky for consumer users long-term. It's unreasonable to expect an individual to have access to their phone, yubikey, or laptop over a period of years. In the B2B space, this isn't as big of a deal. Getting an IT admin that works for your company to reset your access and issue a new credential is not a complex problem. Not so in the B2C space. Devices get lost or stolen, and then the service operator needs to build out an alternative recovery method that needs to be as secure as WebAuthn (ideally, without infringing on the user's privacy via KYC methods). New developments like Apple's PassKeys are super interesting and have the potential to really be a game changer for B2C WebAuthn adoption.

    In summary, WebAuthn probably can't replace the password for your application today, unless your users are tech savvy and OK with the lock-out risk. However, the space going through some exciting changes and it may be much more feasible in a few years!

    [1] https://github.com/w3c/webauthn/wiki/Explainer:-WebAuthn-Con...

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Testing Passkeys / WebAuthn with Spring

    2 projects | dev.to | 6 Jul 2023
  • WebAuthn Is Great and It Sucks

    2 projects | news.ycombinator.com | 2 Jul 2023
  • Challenge code 2fa like github and banks.

    1 project | /r/dotnet | 12 May 2023
  • Creating Passwordless FIDO2 experience

    2 projects | dev.to | 7 Oct 2022
  • Ask HN: How to market my API SaaS?

    1 project | news.ycombinator.com | 2 Aug 2022