Passkey Support
in beta
E
Effective Mouse
Implementing support for storing FIDO2 Passkeys in Hudu where they can be used through the web extension or similar to login to passkey enabled services.
We have requirements for some clients to have FIDO2 or other phishing resistant authentication, but the only way we can do that now is through a separate password manager like Keeper or 1Password.
O
Obedient Whippet
The Hudu Team Before passkeys ship, the browser extension's session model needs to be fixed, because everything built on top of it inherits the same problem.
Two things people should be aware of:
- The extension has no session timeout. Sign in once and it stays signed in indefinitely. There is no idle expiry and no forced re-authentication.
- IP restrictions do not apply to the extension. You can lock the Hudu web app down so nobody can sign in outside your approved ranges, and a tech with the extension already signed in can still use it from anywhere, at any time. The control is bypassable by design.
A question for the team that I haven't been able to test: if a user account is disabled, are active extension sessions revoked immediately? If not, that's an offboarding problem on its own.
The practical consequence: a lost or stolen laptop where BitLocker happened to be off, and whoever has it holds standing access to the vault from any network, with no expiry.
This is already why we don't store TOTP in Hudu. If the password and the second factor both come out of the same permanently signed-in extension, there is no second factor. We pay for a separate platform purely to hold MFA. I have raised this with Hudu directly.
What I'd actually want, and to be clear I am not asking for re-authentication on every OTP reveal or autofill, which isn't workable day to day:
- A configurable session timeout on the extension, with re-authentication after it expires. ScreenConnect's extension is the model here.
- Passkeys should not live in the browser extension at all. Mobile app only.
- In the mobile app, tie stored passkeys to the device's secure element (Secure Enclave / StrongBox / TEE), so the keys are Device-bound and can't be lifted off the device AND not synced.
- New device enrolment requires admin approval before it can hold or assert anything.
- Assertion happens the way FIDO2 hybrid transport already works: unlock the phone, scan the code on screen. That keeps possession and user verification where they belong, on the phone, and gives you proximity as a bonus.
I understand not everyone wants that level of friction, so make it a policy option rather than the default. But it needs to exist for those of us who don't want a single lost laptop to become a full compromise across every client we manage.
The Hudu Team
updated the status to
in beta
B
Big Lemur
Passkeys please!!!
X
Xenon grey Iguana
This is going to become critical once voice & SMS are retired in Microsoft. Current alternatives are not feasible long term
Kristen W.
Merged in a post:
Additional 2FA options in the age of Passkey
S
Subjective Trout
Microsoft has announced that they are getting rid of SMS and Voice. We need Hudu to have another 2FA option like passkey added to maintain security. My hope is that Hudu will add this functionality and we can stay with this platform. Is there anything like this in the works?
Move to phishing-resistant authentication before SMS and voice retire
We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication. Passkeys are becoming the default authentication experience in Microsoft Entra, and Microsoft-provided SMS and voice authentication will retire on February 1, 2027.
For more context on why Microsoft is moving to phishing-resistant authentication by default, please read our Microsoft Security Blog announcement.
What is changing
Passkeys become the default authentication experience for users currently enabled for SMS or voice.
Microsoft-provided telecom delivery for SMS and voice will be retired. Customer-managed telecom providers configured through the Microsoft Security Store are not affected.
E
Electrical Turtle
Some of the comments below are from 2023! How has it been 3 years and this is still not developed?
V
Vertical Pelican
passkeys in general
T
Taupe Swift
We better not get FIDO2 before we get multiple URL's... this is ridiculous!! You are going to force us to use MULTIPLE PASSKEYS to handle MULTIPLE URL?!?!?!?!?!
You gotta be joking yeah? Please tell me you are gonna sneak some extra features into this effort, because supporting FIDO2 has to be a MASSIVE undertaking, while multiple URL support is like 12 lines of code...
D
Dandelion Cobra
How is it that securing the documentation/password platform is less important than implementing AI/MCP Servers? Phishing-resistant authentication is a must! Please vote for FIDO2 authentication. What happens when an MSP employee makes a mistake? Now they have access to all your clients.
Kristen W.
updated the status to
in progress
Load More
→