You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+5-3Lines changed: 5 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,6 +6,8 @@
6
6
7
7
Open-source Windows 11 FIDO2/WebAuthn authenticator with TPM-backed keys, local passkeys, and TOTP.
8
8
9
+
> **Windows 11 passkey manager and software FIDO2/WebAuthn authenticator.** Darks FIDO2 is a local-first virtual passkey provider for passwordless sign-in and TOTP/2FA, using TPM 2.0-backed keys when available.
10
+
9
11
[](https://github.com/darkbyte-JS/DarksFIDO2/actions/workflows/ci.yml)
@@ -14,13 +16,13 @@ Open-source Windows 11 FIDO2/WebAuthn authenticator with TPM-backed keys, local
14
16
> [!WARNING]
15
17
> **Experimental beta.** Current downloads are self-signed, have no SmartScreen reputation, and have not received an independent security audit. Use disposable test accounts, verify SHA-256 checksums, and read the [known limitations](docs/KNOWN-LIMITATIONS.md) before trusting a real account.
- Acts as a Windows plugin passkey manager for browser/app WebAuthn create and get requests.
25
+
- Acts as a Windows 11 virtual passkey provider (software authenticator) for browser/app WebAuthn `navigator.credentials.create()` and `get()` requests.
24
26
- Creates a separate non-exportable ES256 key per virtual passkey, preferring TPM 2.0 and falling back to Microsoft Software KSP.
25
27
- Keeps local passkey records, TOTP seeds, TPM-key metadata, backups, and signed audit history inside independent encrypted profiles.
26
28
- Supports Windows Hello and external USB/NFC/BLE authenticators through the Windows WebAuthn API.
@@ -54,7 +56,7 @@ The portable ZIP runs the manager but cannot install the packaged Windows provid
54
56
|[Known limitations](docs/KNOWN-LIMITATIONS.md)| Distribution, provider, key-management, and test gaps |
|[Security policy](SECURITY.md)| Private reporting and supported versions |
57
-
|[Security audit](SECURITY-AUDIT-0.6.2.md)| Focused maintainer review of CTAP CBOR and Windows WebAuthn |
59
+
|[Security audit](SECURITY-AUDIT-0.6.3.md)| Focused maintainer review of CTAP CBOR and Windows WebAuthn |
58
60
|[Checksums and SBOM](https://github.com/darkbyte-JS/DarksFIDO2/releases)| Per-release SHA-256 file and SPDX dependency inventory |
59
61
60
62
Security-sensitive behavior includes profile-bound HKDF/AES-GCM protection, PBKDF2-HMAC-SHA-256 at 600,000 iterations, DPAPI/TPM wrapping, canonical bounded CTAP2 CBOR, strict native-buffer validation, required UP/UV, local ES256 assertion verification, zeroing of unlocked key arrays, durable protected-file replacement, and transactional keyfile/install flows. See the threat model for what these controls do not protect.
0 commit comments