twofactor_u2f icon indicating copy to clipboard operation
twofactor_u2f copied to clipboard

Webauthn in Nextcloud does only provide 1FA, not 2FA, thus it should not be recommended as a successor to this app

Open RoWo-DS opened this issue 3 years ago • 0 comments

In your documentation, you write "The Two-Factor WebAuthn app can be used as a replacement." to suggest people to migrate from U2F to Webauthn to continue 2FA on Nextcloud.

Webauthn on Nextcloud does not provide 2FA. It only provides 1FA. See https://hwsecurity.dev/2020/08/webauthn-pin-bypass/ for more details.

Please correct your documentation. TOTP could be mentioned as an alternative to U2F for Nextcloud.

RoWo-DS avatar Jul 24 '22 11:07 RoWo-DS