Open Bug 1464888 Opened Last year Updated 2 days ago

Fxa implement WebAuthn U2F / 2FA [feature request]

Categories

(Cloud Services :: Server: Firefox Accounts, defect)

defect
Not set

Tracking

(Not tracked)

UNCONFIRMED

People

(Reporter: davross, Unassigned)

Details

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Firefox/60.0
Build ID: 20100101

Steps to reproduce:

Open Nightly >> Preferences >> Firefox Account


Actual results:

Following implmentation of "two-step authentication" https://blog.mozilla.org/services/2018/05/22/two-step-authentication-in-firefox-accounts/ This works, but is missing the newly Fx Core implementation of WebAuthn.


Expected results:

Now WebAuthn is integrated in Fx 60, and just this week Google finally allowing the use of this for their accounts, the time feels right to roadmap its implementation into the new version of Firefox Accounts.

Doing so would remove our reliance on 3rd parties and enable the use of user's preferred authentication tool for greater personalization.

I've checked with:
https://docs.google.com/spreadsheets/d/1U1IxTOlsaBcRsnJv0XAaVqQLU4otB6h2lG0NDcvWG-E/edit

https://discourse.mozilla.org/c/participationsystems

https://wiki.mozilla.org/SecurityEngineering
Thanks!  The FxA team has been keeping WebAuthn in mind for future integration but haven't made any concrete plans yet, but it's a good time to bring it up as we come into planning for Q3.
Component: Untriaged → Server: Firefox Accounts
Product: Firefox → Cloud Services
I would also love to see this! (also already 8 upvotes here) Q3 is now, is not it? No… there is already Q4, I think. :)
Severity: normal → enhancement

Hope this issue can get more traction. Actually instead of 2FA, FxA is a perfect example where I would like to use WebAuthn passwordless login since extensions seem to be restricted for firefox.com as well and as a result KeePassXC cannot fill in the password for me.

You need to log in before you can comment on or make changes to this bug.