Optimizations for WebAuthn Passwordless Auth

39 views
Skip to first unread message

Florian Ritterhoff

unread,
Jun 12, 2021, 8:24:29 AM6/12/21
to Keycloak Dev
Hi together,

for an event in my master studies we used KeyCloak as Identity Provider. The goal was to realize a complete passwordless authentication. In the course of this, on the one hand a possibility to reset a lost token was created, on the other hand an unusual behavior was noticed, which we have fixed in our opinion. As soon as the user cancelled the registration process for his passwordless account when registering the token (or accidentally deleted his last token), a third party was able to "take over" the account via the login page and the possibly known username.

We would like to contribute these changes to the keycloak project ;)

Thanks and kind regards!

Florian Ritterhoff

unread,
Jun 19, 2021, 2:42:37 PM6/19/21
to Keycloak Dev
Hi,

is there no interest on these changes?
Reply all
Reply to author
Forward
0 new messages