Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Feature Requests
  3. fido2support

fido2support

Scheduled Pinned Locked Moved Feature Requests
security
57 Posts 15 Posters 6.4k Views 16 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S Offline
    S Offline
    simon
    wrote on last edited by
    #15

    Hello,
    I just wanted to emphasise that this topic is super important.
    Now that all browsers and the big tech giants support the topic, more and more websites are offering passkey as a secure and very convenient authentication method. At the latest after Amazon offers passkey as a password replacement (https://www.theverge.com/2023/10/23/23928589/amazon-passkey-support-web-ios-shopping-mobile-app), the topic has finally arrived on the broad market.

    I see two areas of interest for Cloudron here:

    1. cloudron apps with keypass (as 2fa or also as 1fa)
    2. app for developers such as Hanko.io=> https://forum.cloudron.io/topic/8375/hanko-io-fido2-webauthn-passwordless-login
    adisonA 1 Reply Last reply
    1
    • S simon

      Hello,
      I just wanted to emphasise that this topic is super important.
      Now that all browsers and the big tech giants support the topic, more and more websites are offering passkey as a secure and very convenient authentication method. At the latest after Amazon offers passkey as a password replacement (https://www.theverge.com/2023/10/23/23928589/amazon-passkey-support-web-ios-shopping-mobile-app), the topic has finally arrived on the broad market.

      I see two areas of interest for Cloudron here:

      1. cloudron apps with keypass (as 2fa or also as 1fa)
      2. app for developers such as Hanko.io=> https://forum.cloudron.io/topic/8375/hanko-io-fido2-webauthn-passwordless-login
      adisonA Offline
      adisonA Offline
      adison
      wrote on last edited by
      #16

      @simon uh huh.
      thanks for supporting this topic.
      this is hanko, by the way

      my website is not available right now

      1 Reply Last reply
      0
      • adisonA Offline
        adisonA Offline
        adison
        wrote on last edited by
        #17

        another alternative is passwordless.dev, i think

        my website is not available right now

        1 Reply Last reply
        0
        • nebulonN nebulon

          as said I didn't look again into that so far. Last time I attempted, I only managed to get it to work on chrome, but not on firefox. The attempt was with the https://www.npmjs.com/package/fido2-lib module back then.

          S Offline
          S Offline
          simon
          wrote on last edited by
          #18

          @nebulon maybe because you use Linux? Unfortunately, the support there is still very poor, but it looks much better on other devices. https://www.passkeys.io/compatible-devices

          adisonA 1 Reply Last reply
          0
          • S simon

            @nebulon maybe because you use Linux? Unfortunately, the support there is still very poor, but it looks much better on other devices. https://www.passkeys.io/compatible-devices

            adisonA Offline
            adisonA Offline
            adison
            wrote on last edited by
            #19

            @simon yeah true

            my website is not available right now

            1 Reply Last reply
            0
            • adisonA adison referenced this topic on
            • adisonA adison referenced this topic on
            • A Offline
              A Offline
              adisonverlice2
              wrote on last edited by
              #20

              alright, i'm wondering what improvements have been made sense this topic rolled out.

              remember, don't overlook security. be safe online

              1 Reply Last reply
              0
              • sponchS Offline
                sponchS Offline
                sponch
                wrote on last edited by
                #21

                Looking forward to it 🙂

                1 Reply Last reply
                0
                • C Offline
                  C Offline
                  crazybrad
                  wrote on last edited by
                  #22

                  @adison +1 for passwordless.dev. Looks really interesting. We have been considering implementing passwordless in one of our applications and their generous user allowance makes a powerful business case. Seems to fit the Cloudron culture as well.

                  A 1 Reply Last reply
                  0
                  • C crazybrad

                    @adison +1 for passwordless.dev. Looks really interesting. We have been considering implementing passwordless in one of our applications and their generous user allowance makes a powerful business case. Seems to fit the Cloudron culture as well.

                    A Offline
                    A Offline
                    adisonverlice2
                    wrote on last edited by
                    #23

                    @crazybrad 1. witch app? and2. that is really coll man. yeah it does. i cant wait to see how this is going to go along with cloudron. not only that, i think it'll give bitwardens passwordless team a head because cloudron is not large, but pretty good in size. if i were you, what i would do is have it to where all the user has to do is give cloudron dashboard the key, then cloudron will do the other stuf unless required on the users end.

                    remember, don't overlook security. be safe online

                    1 Reply Last reply
                    0
                    • C Offline
                      C Offline
                      crazybrad
                      wrote on last edited by
                      #24

                      @adisonverlice2 We have a proprietary application (not hosted on Cloudron). I have considered using Cloudron as the single source of authentication truth, but for various reasons, I will likely not go in that direction.

                      A 1 Reply Last reply
                      0
                      • C crazybrad

                        @adisonverlice2 We have a proprietary application (not hosted on Cloudron). I have considered using Cloudron as the single source of authentication truth, but for various reasons, I will likely not go in that direction.

                        A Offline
                        A Offline
                        adisonverlice2
                        wrote on last edited by
                        #25

                        @crazybrad i see. that is very cool.

                        remember, don't overlook security. be safe online

                        1 Reply Last reply
                        0
                        • A Offline
                          A Offline
                          adisonverlice2
                          wrote on last edited by
                          #26

                          i just thought of another way to do fido support.
                          have cloudron users use something like duo security and then login can be done using fido along with other ways cloudron does not natively support.

                          remember, don't overlook security. be safe online

                          1 Reply Last reply
                          0
                          • A Offline
                            A Offline
                            adisonverlice2
                            wrote on last edited by
                            #27

                            by the way, that link was a link from security now, a podcast i regularly listen to.
                            here is the official duo security address.
                            my business has used it before, so i think its pretty good at what it does.

                            remember, don't overlook security. be safe online

                            1 Reply Last reply
                            0
                            • J Offline
                              J Offline
                              Jarod
                              wrote on last edited by
                              #28

                              Hey!

                              Just want to push this. Would be cool to add password less authentication to Cloudron 🙂

                              1 Reply Last reply
                              3
                              • brerlapnB Offline
                                brerlapnB Offline
                                brerlapn
                                wrote on last edited by
                                #29

                                @girish and @nebulon There's another resource like passwordless.dev that is maintained by members of the W3C and FIDO Alliance team that developed passkeys: https://passkeys.dev/ Even if it's tricky to implement passkey support for applications we host in Cloudron, being able to log in to the admin panel with a passkey would be massive as this provides the security of PKI encryption without the overhead nightmare of running a certificate authority.

                                It includes libraries and guides for thinking through the implementation. Mastodon handles are on the landing page, too, if you have questions. They maintain the site on their own to help orgs looking to adopt passkeys and one of the maintainers is the author of the SimpleWebAuthn (https://github.com/MasterKale/SimpleWebAuthn)

                                Bitwarden supports passkeys with their iOS mobile app now and in their beta Android app, and 1Password supports them in both mobile apps, so the ecosystem is at a point where there's full cross-platform support (except Linux dammit, but browser-based passkeys will work on Linux) and it's not just iOS or Chrome Password Manager.

                                1 Reply Last reply
                                4
                                • A Offline
                                  A Offline
                                  adisonverlice2
                                  wrote on last edited by
                                  #30

                                  i'm glad i've made this more of a trending topic on the forum.
                                  this should push more support for FIDO in cloudron.

                                  remember, don't overlook security. be safe online

                                  1 Reply Last reply
                                  3
                                  • nebulonN nebulon referenced this topic on
                                  • I Offline
                                    I Offline
                                    IniBudi
                                    wrote on last edited by
                                    #31

                                    Yes, hopefully, this idea can be implemented in the next Cloudron update. I support this FIDO2 WebAuthn so we can log in to 2FA and approve the login process using our phone. 😄

                                    1 Reply Last reply
                                    0
                                    • N Offline
                                      N Offline
                                      nostrdev-com
                                      wrote on last edited by
                                      #32

                                      FID02 would be a great security upgrade

                                      1 Reply Last reply
                                      1
                                      • matix131997M Offline
                                        matix131997M Offline
                                        matix131997
                                        wrote on last edited by
                                        #33

                                        I did a test today on a laptop running ZorinOS 17.1 with kernel 6.5.

                                        I can confirm the two-way operation of the system using a QR key with Apple iPhone. On the website 'passkeys.io' I was able to write the key as well as read it.

                                        A 1 Reply Last reply
                                        0
                                        • matix131997M matix131997

                                          I did a test today on a laptop running ZorinOS 17.1 with kernel 6.5.

                                          I can confirm the two-way operation of the system using a QR key with Apple iPhone. On the website 'passkeys.io' I was able to write the key as well as read it.

                                          A Offline
                                          A Offline
                                          adisonverlice2
                                          wrote on last edited by
                                          #34

                                          @matix131997 o cool!

                                          remember, don't overlook security. be safe online

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Bookmarks
                                          • Search