ASVS icon indicating copy to clipboard operation
ASVS copied to clipboard

WebAuthn / Web Authentication API

Open RafaelGreen1 opened this issue 2 years ago • 2 comments

Hi, I searched the standard (V2 Authentication) for recommendation of using the Web Authentication API / WebAuthn but didn't find any information about it. Are there any recommendations regarding using it? Thanks,

RafaelGreen1 avatar May 16 '22 08:05 RafaelGreen1

The current 2.2.9 mandates MFA, 2.2.4 mandates a hardware based authenticator. Do you think that covers it?

tghosth avatar Jun 21 '22 13:06 tghosth

well, I think 2.2.4 covers it. But, In my opinion WebAuthn is the future of web authentication with many advantages and great support. If it was up to me I would mention it, but anyway its included in 2.2.4

RafaelGreen1 avatar Jul 31 '22 06:07 RafaelGreen1

I am going to close this because I have a wider question on 2.2.4 in #1340 which I will incorporate this into.

tghosth avatar Aug 24 '22 14:08 tghosth