# Yubikey/U2F Key Support

**URL:** https://meta.discourse.org/t/yubikey-u2f-key-support/88543
**Category:** Feature
**Created:** [5월 27, 2018, 4:53오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543 "2018-05-27T16:53:25Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![nsuchy](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nsuchy/32/166530_2.png) [@nsuchy](https://meta.discourse.org/u/nsuchy)
#### Post date: [5월 27, 2018, 4:53오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/1 "2018-05-27T16:53:25Z")

</div>

Would the developers of Discourse consider allowing us to use U2F Keys for 2-factor authentication?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [5월 28, 2018, 5:11오전 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/2 "2018-05-28T05:11:55Z")

</div>

As I understand it, browser support is still too immature to do so. Feel free to cite relevant examples for Safari, Edge, Chrome, and Firefox.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [5월 28, 2018, 5:46오전 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/3 "2018-05-28T05:46:39Z")

</div>

Yes as far as I know only Chrome adopted this standard. I agree we got to wait here, or someone can build a plugin.

---

<div class="post-metadata">

### Author: ![Cameron\_D](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/cameron_d/32/97535_2.png) [@Cameron\_D](https://meta.discourse.org/u/Cameron_D)
#### Post date: [5월 28, 2018, 7:06오전 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/4 "2018-05-28T07:06:17Z")

</div>

Edge: [https://developer.microsoft.com/en-us/microsoft-edge/platform/status/fidou2f/?q=U2F](https://developer.microsoft.com/en-us/microsoft-edge/platform/status/fidou2f/?q=U2F) Not planned.

Firefox: [Security/CryptoEngineering - MozillaWiki](https://wiki.mozilla.org/Security/CryptoEngineering) Supported in 57.

Safari: [GitHub - Safari-FIDO-U2F/Safari-FIDO-U2F: FIDO U2F support for Safari. · GitHub](https://github.com/Safari-FIDO-U2F/Safari-FIDO-U2F) available via plugin.

---

<div class="post-metadata">

### Author: ![gerhard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/gerhard/32/119479_2.png) [@gerhard](https://meta.discourse.org/u/gerhard)
#### Post date: [5월 28, 2018, 9:46오전 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/5 "2018-05-28T09:46:39Z")

</div>

It should be possible when [WebAuthn](https://w3c.github.io/webauthn/) is supported by major browsers. It’s already part of Firefox 60, will probably be in Chrome 67 and as far as I know it will be added to Edge and Safari in the near future.

> **[FIDO Alliance and W3C Achieve Major Standards Milestone in Global Effort...](https://www.w3.org/press-releases/2018/webauthn-fido2/)**
>
> With support from Google Chrome, Microsoft Edge and Mozilla Firefox, FIDO2 Project opens new era of ubiquitous, phishing-resistant, strong authentication to protect web users worldwide

---

<div class="post-metadata">

### Author: ![haikuos](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/haikuos/32/119820_2.png) [@haikuos](https://meta.discourse.org/u/haikuos)
#### Post date: [6월 27, 2018, 12:43오전 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/6 "2018-06-27T00:43:26Z")

</div>

+1 I’d like to see U2F support as well.

Gitlab supports U2F by requiring users who want to leverate it to sign up for 2-factor authentication first… then if the user is unable to log-in via a U2F dongle (not accessible, browser lacks support, etc), they can do the normal authy/authenticator 2-factor.

U2F dongles are also getting _cheap_. [Amazon.com: FIDO U2F Security Key, Thetis [Aluminum Folding Design] Universal Two Factor Authentication USB (Type A) for Extra Protection in Windows/Linux/Mac OS, Gmail, Facebook, Dropbox, SalesForce, GitHub : Electronics](http://a.co/8Q4C20f)

---

<div class="post-metadata">

### Author: ![marianord](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/marianord/32/90502_2.png) [@marianord](https://meta.discourse.org/u/marianord)
#### Post date: [8월 19, 2018, 2:36오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/7 "2018-08-19T14:36:32Z")

</div>

I think the approach of Gitlab would be the ideal, if the U2F is not available fallback to the _traditional_ 2FA.

Google is already launching its own U2F key, so that will speed up the adoption and will ensure full support in all Google products.

That would keep Discourse in the lastest security measures.

Here is all the info about the adoption FIDO-U2F is getting

> **[FIDO Alliance Overview | FIDO Alliance](https://fidoalliance.org/overview/)**
>
> Learn how FIDO Alliance is using open, phishing-resistant standards to change authentication by reducing the world's reliance on passwords with with passkeys.

---

<div class="post-metadata">

### Author: ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)
#### Post date: [8월 19, 2018, 4:29오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/8 "2018-08-19T16:29:03Z")

</div>

There are also U2F tools like [https://krypt.co](https://krypt.co) which are very handy to use. Integration of U2F in general will be much welcome.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [8월 19, 2018, 11:31오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/9 "2018-08-19T23:31:38Z")

</div>

Yes, this is unavoidable at the moment cause even the Yubikey neo does not support u2f on iPhone X despite NFC.

Not against adding this, but there is no rush here.

---

<div class="post-metadata">

### Author: ![rugk](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rugk/32/158661_2.png) [@rugk](https://meta.discourse.org/u/rugk)
#### Post date: [10월 12, 2018, 2:48오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/10 "2018-10-12T14:48:17Z")

</div>

> [@sam](#):
>
> Yes, this is unavoidable at the moment cause even the Yubikey neo does not support u2f on iPhone X despite NFC.

The reason for that is just that Apple does not allow NFC to do this stuff. So no U2F key supports that…  
However, obviously, that is not an argument again implementing this, if just one platform has does not properly implement support for that.  
And, of course, you should always be able to use another 2FA mode (if configured) as a fallback if you cannot use FIDO U2F/WebAuthn keys (and yes, there are [more](https://solokeys.com/) [than](https://u2fzero.ch/) [YubiKeys](https://www.nitrokey.com/)).

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [10월 12, 2018, 2:54오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/11 "2018-10-12T14:54:12Z")

</div>

> **[Can I use... Support tables for HTML5, CSS3, etc](https://caniuse.com/#feat=webauthn)**
>
> "Can I use" provides up-to-date browser support tables for support of front-end web technologies on desktop and mobile web browsers.

Once Edge supports it, then Safari needs to fall in line. Not there yet.

---

<div class="post-metadata">

### Author: ![Rafe](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rafe/32/105093_2.png) [@Rafe](https://meta.discourse.org/u/Rafe)
#### Post date: [12월 14, 2018, 12:20오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/12 "2018-12-14T12:20:29Z")

</div>

Safari support is incoming: [Release Notes for Safari Technology Preview 71 | WebKit](https://webkit.org/blog/8517/release-notes-for-safari-technology-preview-71/)

I think it’s worthwhile to point out people don’t need to buy a physical security key to use WebAuthn:

- Chrome desktop allows the use of Macbook fingerprint scanner to log in
- Chrome Android can use fingerprint and screen lock pattern/PIN to authenticate
- MS Edge can use Windows Hello face and fingerprint scanners

I expect Apple to include TouchID/FaceID in the final version of Safari - and that these platform authenticators will be much more attractive for end-users than a roaming authenticator (Yubikey and the like).

FWIW I’ve played around with this gem: [GitHub - cedarcode/webauthn-ruby: WebAuthn ruby server library ― Make your Ruby/Rails web server become a conformant WebAuthn Relying Party · GitHub](https://github.com/cedarcode/webauthn-ruby)

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [12월 14, 2018, 5:42오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/13 "2018-12-14T17:42:10Z")

</div>

> [@Rafe](#):
>
> expect Apple to include TouchID/FaceID in the final version of Safari

Yes, this would be fantastic. Huge fan of face login, I use it in Windows 10 and of course on new iPad and iPhone.

---

<div class="post-metadata">

### Author: ![L30110](https://avatars.discourse-cdn.com/v4/letter/l/eb9ed0/32.png) [@L30110](https://meta.discourse.org/u/L30110)
#### Post date: [12월 25, 2018, 8:32오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/14 "2018-12-25T20:32:12Z")

</div>

With MS killing off Edge per se in favor of a Chromium based browser, “traditional” Edge seems to no longer be a significant factor.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [12월 25, 2018, 8:37오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/15 "2018-12-25T20:37:01Z")

</div>

Yes, that is one bright spot in that news story – we only need to wait for Safari now on this particular feature.

It’s [generally not great news though](https://www.smashingmagazine.com/2018/12/internet-explorer-what-we-wished-for/).

---

<div class="post-metadata">

### Author: ![L30110](https://avatars.discourse-cdn.com/v4/letter/l/eb9ed0/32.png) [@L30110](https://meta.discourse.org/u/L30110)
#### Post date: [12월 25, 2018, 8:43오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/16 "2018-12-25T20:43:03Z")

</div>

[Apple testing USB security key support for Safari | AppleInsider](https://appleinsider.com/articles/18/12/05/apple-testing-usb-security-key-support-for-safari)

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [12월 25, 2018, 8:46오후 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/17 "2018-12-25T20:46:30Z")

</div>

Less competition is never good news, particularly when there’s a good chance [anticompetitive behavior may have squashed the small guy](https://news.ycombinator.com/item?id=18697824). How the tables have turned.

---

<div class="post-metadata">

### Author: ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)
#### Post date: [3월 6, 2019, 4:46오전 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/18 "2019-03-06T04:46:41Z")

</div>

webAuthn is now official

> **[W3C and FIDO Alliance Finalize Web Standard for Secure, Passwordless Logins](https://www.w3.org/press-releases/2019/webauthn/)**
>
> Major browsers and platforms have built-in support for new Web standard for easy and secure logins via biometrics, mobile devices and FIDO security keys

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [3월 6, 2019, 4:54오전 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/19 "2019-03-06T04:54:48Z")

</div>

Yep, just needs to make its way into all the main production browsers now.

Oh, and iOS. No biggie 🤣

---

<div class="post-metadata">

### Author: ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)
#### Post date: [3월 6, 2019, 5:05오전 UTC](https://meta.discourse.org/t/yubikey-u2f-key-support/88543/20 "2019-03-06T05:05:10Z")

</div>

Firefox ✅  
Chrome ✅  
MS Edge ✅  
Android ✅  
Safari desktop Preview - works with some tweaks  
Safari Mobile 🚫

[다음 페이지](https://meta.discourse.org/t/yubikey-u2f-key-support/88543.md?page=2)
