Discussion about this post

User's avatar
wayne reeser's avatar

no luck with samsung, including the s25 (I have not tested since the april security patch) but yubikeys do not work well on samsung devices, my intent was to lock down my google account by putting the passkey on the yubikey, and I hoped, using NFC. NFC is out completely, but I can't get it to work via USB either, I need to disable TOTP for it to possibly work, I have not tried that yet. For now everything has to go into a password manager and/or authenticator app:

I bought 4 keys to have backups and one for my spouse, and I can't even use them as I expected to be able to do, based on the documentation.

from yubikey support:

I can understand your concern and frustration with attempting to get Samsung devices with FIDO2 that google and many financial accounts use. There are several reasons why you are encountering problems and they are all due to the design and implementation of Samsung and Android. To start with, we have noticed some FIDO2(aka passkey) flows with Samsung will fail if you have the Yubico OTP enabled. You would need to disable the Yubico OTP and this will allow it to function, in our test cases. We have informed Samsung as it is appears they will need to do a firmware update to fix this issue. You can find the specifics in this documentation found here:

https://support.yubico.com/hc/en-us/articles/18801283920156-FIDO-issues-on-Samsung-devices

The second issue is more general and specific to Android, first, Passkeys will only work via USB. This is due to NFC not being supported for Passkeys at this time. On top of this there are other issues with Android we have noticed, and some of them have work arounds and some do not. You can find out more information about this here:

https://support.yubico.com/hc/en-us/articles/17865198749852-Android-known-issues-with-FIDO2

Expand full comment
Steve B Rawls's avatar

Well written and researched. Thanks, Champ!

Expand full comment
1 more comment...

No posts