Universal Second Factor and Qubes OS 4.2: can we still use our old U2F keys?
10-07, 14:20–14:50 (Europe/Berlin), Social Hub Main Room

During the talk, I will introduce the CTAP2 proxy service in the Qubes OS, which replaces the older U2F proxy. Our new service has been designed to ensure compatibility with the new Fido2 standard, thus enabling the full capabilities of newer hardware keys such as device PIN. Throughout the presentation, we will delve into the details of the newly introduced qrexec policies and consider the issue of backward compatibility. Spoiler alert: you may not even notice the upgrade.

See also: slides (971.1 KB)

Qubes OS developer