UEFI support for FIDO2/U2F

Hey!

I just learned that Insyde is actually supporting FIDO2 authentication for their BIOS since several years now [0]!

As long as we’re able to use multiple nitrokeys/yubikeys/… in parallel (in case of broken or lost keys), I’d be very interested in getting that feature on our frameworks. What does the rest of the community think - would you be interested in such a thing?

Is anybody aware what we’d have to do to get that? If Framework is currently not compiling that in/activating it, who do we need to poke to get it activated? :wink:

[0] InsydeH2O® UEFI BIOS Adds Additional Boot Protection with FIDO Authentication Support - Insyde Software

2 Likes

Cool. I’ll set it up and use it. Go yubikey go Framework!

I believe this user is asking whether Framework will support it. It is not supported on Framework devices today.

I’m sure it’s supported. Except for BIOS, which makes sense since this is before the OS even boots. Using it for LUKS2 unlock would be great as well but that falls in the same category.

That is the entire purpose of this thread. It supported in the firmware for the purposes of authenticating to the firmware.

1 Like

I’d love to see this added! Any progress adding FIDO2 to our daily workflows is a win in my books. Bonus points if we could see this even on the older boards

Exactly. I am already using FIDO2 keys for LUKS or local authentication. Just for the BIOS I have to keep a long random password lying around.

Does anybody here know a contact we can ping about that? Since it’s not about implementing something, but simply using what is already supported by the vendor, I am a little bit optimistic we actually might get it :slight_smile:

And yes, @aHumanPerson , I’d also like them for my 7840 boards (13" and 16"). Let’s see…