signup: make passkey the primary choice, and name the cost of the password path #166
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web#166
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Why
Every person is already required to hold MFA — the identity provider's account policy on
idm_all_personssetscredential_type_minimum = mfa. A passkey ranks abovemfaand satisfiesthat policy on its own, so a passkey user never sees a second-factor prompt. A password user must
additionally enrol TOTP, which means installing an authenticator app.
Both branches are presented today as an even choice. The sign-up step reads "choose how you sign
in — set a passkey or password", and the FAQ opens with "No, a password works too." A user picking
"password" is therefore opting into the authenticator-app path without being told so, which is the
single largest avoidable source of onboarding friction we have.
Platform authenticators (Face ID, Touch ID, Windows Hello, Android biometrics) are less work than
a password: nothing to install, nothing to transcribe, no clock skew, and they cannot be phished.
Upstream calls passkeys "the preferred method of authentication" and has been retiring the
alternatives — security keys as a second factor were deprecated for removal, with the note that
"Security Keys are surpassed by PassKeys which give a better user experience".
Scope
secondary one.
setting up an authenticator app.
neutral.
Explicitly out of scope
Do not raise
credential_type_minimumtopasskey. There is noreset-credential-type-minimum, downgrades are restricted, and it would lock out everypassword-only person including break-glass, with no way back. This issue is about steering, not
enforcement.
Done when
Sign-up and the FAQ both make passkey the default reading, the password path names its own cost,
and both languages pass the style check.
Part of gitborg/gitborg-docs#69.
supernaut refererade till detta ärende från bitborg/bitborg-docs2026-08-02 12:32:47 +00:00