FIDO2 support for macOS and Linux desktop client

Calendar year :sunglasses: - the Gregorian calendar, specifically :rofl::rofl::rofl:

4 Likes

The updated roadmap no longer specifically calls out this feature. Has it fallen off, or just no longer worth of being called out specifically?

1 Like

It’s still there :slight_smile: - we’ll update the image for the roadmap timeline to reflect it.

Looks like the most recent roadmap update only calls out the mobile apps. Are desktop apps covered by any of the roadmap items or is it no longer a planned feature?

1 Like

Windows desktop is already live with FIDO2, macOS is in progress :+1:

2 Likes

Great news!

Sorry to be “that guy”, how about Linux?

3 Likes

Mobile is underway:

@codemichael I’ll have to check on Linux timing, but overall Fido2 is a big priority for us :+1:

3 Likes

I just downloaded from playstore and FIDO2 on Android does not appear to be working with my Yubikey NFC and 5c. Only OTP works, same as last year. After I disabled Yubikey OTP, the android app now says “Login Unavailable … none of the configured two-step providers are supported on this device.” Android app does not even attempt to read via NFC. It’s back to KeePass again.

1 Like

@Hans_Mata hang tight! We’re about to release FIDO2 support in the next app version later this week.

2 Likes

Any (iOS) TestFlight available for this, by chance? :slightly_smiling_face:

It was just published in the App Store actually! :tada:

2 Likes

Not yet available for self-hosted? /webauthn-mobile-connector, is live at Bitwarden Mobile WebAuthn Connector, but I am not seeing it in the nginx config on github nor on the latest released self-hosted version.

Ah! Not quite yet :relaxed:

The self hosted updates are normally delayed a few days as we monitor the release on our SaaS solution.

Still not working with Yubikey 5c and Yubikey NFC, via NFC nor USB-C. With the 5c, I get two vibrations then it goes to Yubikey OTP site. If I disconnect immediately after one vibration, nothing happens.

With Yubikey NFC, nothing happens.

I guess it’s back to KeePass again.

@tgreer any news for this on MacOS. Would really like to get rid of Authy and only use my shiny new yubikey with webauthn.

Heh, I understand! I think we are still waiting on an Electron fix for this and another request with TouchID.

@hinton do you happen to know the issue with electron specifically?

Please put this on a high priority because it tampers security. As I am not using the Desktop app very often I think I will drop it completely until webauthn will be implemented.

Thanks for the reply @tgreer

We are blocked by Electron not supporting the WebAuthn dialogs on macOS, feat: webauthn dialog support by sentialx · Pull Request #28349 · electron/electron · GitHub.

Thank you @Hinton.
This really messes things up

This feature seems to be at every other platform besides MacOS, so can you implement this feature for the MacOS desktop app as well. The weird part is that in the last Vault Hours this was asked, but the team said that it is already implemented even though it isn’t.