Skip to content
This repository has been archived by the owner on Nov 7, 2023. It is now read-only.

Be VERY careful when you use this!Β #54

Open
@markg85

Description

Hi,

Right now i'm in the awkward position where a site DID allow me to set a security key.
Krypton did pop up to confirm the "registration" if you will.

The trouble comes when you want to login.
And... the login keeps asking for a (yubi)key and doesn't trigger krypton.
This happens on a few sites and is a major pain in the *** to get back into working order.
As there you have the situation where, for the registration, krypton popped up. But to login it doesn't.

So, just a fair warning. I've been bitten by this a couple times now.
Be extremely careful when using krypton!

I think it's a failure on Krypton's end to not catch those cases correctly. Even though you can argue that the login mechanism on those sites (binance.com is one such example) are just poorly done. But they work if you have a yubikey. Which, to be frank, is the correct way for them to support.

Don't get me wrong though. It's super awesome to use, for example, webauthn.io and see it work with krypton :)

Cheers,
Mark

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions