REG: Wrong Pin Device reset Issue

57 views
Skip to first unread message

Srinath Velavan

unread,
May 5, 2026, 9:01:58 AM (yesterday) May 5
to FIDO Dev (fido-dev)
Hi, 

I am trying to implement CTAP 2.3 updates to FIDO2 security key. According to the standards, after the final wrong pin attempt the device gets locked and displays the message " You've entered incorrect PINs too many times. Use a different sign-in option, or contact your IT support person"

At this point, there should no longer be an option to enter the PIN whether the right pin or wrong pin according to old standards (CTAP 2.0,2.1etc). But, the prompt still allows you to enter the pin again and loops to the same message. Is this the normal operation in CTAP 2.3 or is there a bug in Windows? The prompt works fine with MAC OS.

However, if i disconnect the device or change sign-in option, only the message appears and doesn't let me enter the PIN. 

Please refer to the attached screenshots.


Screenshot 2026-05-04 122333.png
Screenshot 2026-05-04 123245.png

My1

unread,
May 5, 2026, 9:24:37 AM (yesterday) May 5
to Srinath Velavan, FIDO Dev (fido-dev)
well I assume windows as the client does not actively check the retry counter before asking for the PIN, and only sees the big error message when the PIN is submitted.

--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to fido-dev+u...@fidoalliance.org.
To view this discussion visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/e173ccba-cd5f-4540-861a-1bc71e3beb67n%40fidoalliance.org.
Reply all
Reply to author
Forward
0 new messages