nonsensical PINs and retry counter

51 views
Skip to first unread message

My1

unread,
Jul 18, 2025, 2:38:17 PMJul 18
to FIDO Dev (fido-dev)
Hi again,

stupid question out of curiosity.

is it allowable to not decrease the retry counter if the PIN fundamentally does not make sense 

1) either by CTAP basic standards (less than 4 characters as well as empty)

2) by a firmware-level policy (that specicially means a policy that cannot be disabled or reduced)

I would say it would massively help users, especially those with all sorts of accessibility problems (who might accidentially submit too early), or those who forgot the complexity requirements of their FIDO Device (we all know the standard problem where you forget your password and after learning the complexity requirements you get the classic "your new password cannot be the same as your old one" once you have the complexity dialed in)
Reply all
Reply to author
Forward
0 new messages