Secure database with FIDO2/HMAC-SHA1, while also allowing unlock with an iOS passkey. #13313
Answered
by
droidmonkey
dungadaman
asked this question in
Q&A
|
I have secured the database with a YubiKey NFC, and the database is stored on my PC. I also sync the database to my iPhone. The logistical issue is that I do not always have the YubiKey with me. It is usually near my PC, not with me when I am using my iPhone. Is it possible to unlock the database on the iPhone without the YubiKey, for example by using an iOS passkey? I suspect that the only solution is to duplicate the HMAC-SHA1 configuration to another YubiKey and always keep that key with my phone all the time whenever i need to unlock the database. |
Answered by
droidmonkey
May 5, 2026
Replies: 2 comments 1 reply
|
No, you need the yubikey to unlock or duplicate the secret on another key. |
1 reply
Answer selected by
phoerious
|
Strongbox lets you duplicate the HMAC configuration to the iphone's secure enclave and have it unlock locally. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
No, you need the yubikey to unlock or duplicate the secret on another key.