Useful explanation, even in 2024. Particularly useful for devs who actually have to implement .create and .get and parse the responses to each on the backend. Thanks!:face-blue-smiling:
Thank you, codekaiju Nick! An excellent explanation of the WebAuthn components in FIDO2.
Hey Nick, I love the Douglas Adams quote at 5:18. Nice! :-)
Good stuff! Does the authenticator store public and private keys created during the registration process on to the authenticator device (yubikey) for retrival during login or is it generated again during login?
Is there a way to authenticate via my organization's mobile app? I want to send a notification from my organization's web app to the mobile app. If the mobile app user approves the login by pressing the "Approve" button, the system should allow the login.
Well explained! wondering if anyone has any pointers like how to automate the registration/authentication process for these backend API calls?
I got lost after about 20 minutes and then I started to feel like a moron. If anyone feels the same way, just try it again. It's not the fault of the presentation, it's just that it's really such a complex topic.
This should be published years earlier when I was trying to implement it.
Can we hide the webservice? Like : I don't want to allow anybody to know the first page unless using this FIDO2 tech ?
Too good.
@APrintmaker