<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FIDO2 Pin Entry dialog looks too generic. in Discussions</title>
    <link>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/81914#M31336</link>
    <description>&lt;P&gt;Yeah, good idea&lt;/P&gt;&lt;P&gt;Though not sure what alternative should be used for linux based OSes.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Dec 2024 10:54:19 GMT</pubDate>
    <dc:creator>selimrecep</dc:creator>
    <dc:date>2024-12-24T10:54:19Z</dc:date>
    <item>
      <title>FIDO2 Pin Entry dialog looks too generic.</title>
      <link>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/64431#M22688</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I use a FIDO2 token to secure my accounts (NitroKey), and on some sites it'll prompt for the device PIN. Unfortunately, this dialog appears to be really generic, in the sense that it might be easily faked by some JavaScript code or something of the sort. This feels like it could be a bit of a security vulnerability, or at least make it easier for attackers to trick people into handing over their token PINs.&lt;/P&gt;&lt;P&gt;My suggestion is to add some sort of icon that can't be triggered using JavaScript - maybe a key icon or something?&lt;/P&gt;&lt;P&gt;I've attached an image of what the dialog looks like for me - maybe it's a bit different on different platforms but this is what I get on all of my Linux computers.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 15:08:48 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/64431#M22688</guid>
      <dc:creator>fwfy</dc:creator>
      <dc:date>2024-08-08T15:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 Pin Entry dialog looks too generic.</title>
      <link>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/65804#M23315</link>
      <description>&lt;P&gt;On Ubuntu 23.04 the appearance looks same, this is definitely easy to spoof. Chrome has a nice UI to prompt for PIN, it doesn't have to look good, just needs to look distinguishable. Practically I don't find it okay to use keys on firefox for now.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 18:25:04 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/65804#M23315</guid>
      <dc:creator>selimrecep</dc:creator>
      <dc:date>2024-08-23T18:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 Pin Entry dialog looks too generic.</title>
      <link>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/65808#M23317</link>
      <description>&lt;P&gt;Just easy as a simple&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;val = prompt("Please enter the PIN for your device.")&lt;/LI-CODE&gt;&lt;P&gt;Edit: You could say the one in attachment is narrower etc. but all those properties could be changed by an update, so not significant enough to rely on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 18:43:06 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/65808#M23317</guid>
      <dc:creator>selimrecep</dc:creator>
      <dc:date>2024-08-23T18:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 Pin Entry dialog looks too generic.</title>
      <link>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/77739#M29660</link>
      <description>&lt;P&gt;On Windows it could use the Windows Security window.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2024 17:00:35 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/77739#M29660</guid>
      <dc:creator>rogue-agent</dc:creator>
      <dc:date>2024-11-11T17:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: FIDO2 Pin Entry dialog looks too generic.</title>
      <link>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/81914#M31336</link>
      <description>&lt;P&gt;Yeah, good idea&lt;/P&gt;&lt;P&gt;Though not sure what alternative should be used for linux based OSes.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 10:54:19 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/fido2-pin-entry-dialog-looks-too-generic/m-p/81914#M31336</guid>
      <dc:creator>selimrecep</dc:creator>
      <dc:date>2024-12-24T10:54:19Z</dc:date>
    </item>
  </channel>
</rss>

