Groups keyboard shortcuts have been updated
Dismiss
See shortcuts

Inquiry about CDA UI/UX Rules

70 views
Skip to first unread message

HYUN TAEK

unread,
Mar 18, 2025, 9:28:28 PMMar 18
to FIDO Dev (fido-dev)
Hello,

I am operating a FIDO2 system at my company. I am preparing guidance for users of the FIDO2 system regarding the issue described below and would like to understand whether there are consistent rules governing the UI/UX for this behavior.

I am particularly interested in the UX of the authenticator selection screen provided by Chrome or Edge browsers in a Windows 10 environment.

For example, in some versions of Chrome, the Windows Hello popup is prioritized, and if the user cancels the Windows Hello popup, the authenticator selection screen is then displayed.
On the other hand, in other versions of Chrome, the authenticator selection screen is displayed first, before the Windows Hello popup.

What could be the reason or cause of these UX inconsistencies?
Is there a way to ensure a consistent UX experience across all cases? For example, making sure that the Windows Hello popup is always prioritized, and only after canceling it, the authenticator selection screen is displayed.

Tim Cappalli

unread,
Mar 18, 2025, 10:32:58 PMMar 18
to HYUN TAEK, FIDO Dev (fido-dev)
Windows 10 (and some early versions of Windows 11) do not support CDA natively, and some WebAuthn Clients provide that functionality (Chrome and Edge). In those cases, you'll see initial authenticator selection handled by Chrome and Edge, and then handed off to the client platform. 

The other case, specific to Chrome, is when the user uses Google Password Manager as their credential provider. In that case, Chrome will also handle authenticator selection for create calls, and sometimes for get if there's a credential in GPM. 

This presentation may help further explain all this: https://blog.timcappalli.me/p/preso-authn24-passkeysonion/

tim

--
You received this message because you are subscribed to the Google Groups "FIDO Dev (fido-dev)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to fido-dev+u...@fidoalliance.org.
To view this discussion visit https://groups.google.com/a/fidoalliance.org/d/msgid/fido-dev/80ab9199-710f-4f8c-8919-8aac81547de2n%40fidoalliance.org.
Reply all
Reply to author
Forward
0 new messages