Hacker News new | ask | show | jobs
by zxcvgm 2889 days ago
FIDO2 is an improvement over the U2F standard, mainly with the ability to now perform password-less logins [1][2]. This had to do with a shortcoming in the U2F protocol and/or devices such that they didn't need to have much storage on these devices [3]. To address this, the new FIDO2 devices are now required to persist your username(s) for a particular site. The new CTAP2 protocol has also been extended to accommodate more sophisticated authenticators, like those crypto-currency wallets with a display.

If you are looking for devices, check out reviews of various devices by agl [4] and Brad Hill [5].

[1] https://www.yubico.com/2018/04/yubico-and-microsoft-introduc...

[2] https://fidoalliance.org/fido2/

[3] https://www.yubico.com/2014/11/yubicos-u2f-key-wrapping/

[4] https://www.imperialviolet.org/2017/10/08/securitykeytest.ht...

[5] https://github.com/hillbrad/U2FReviews