Skip to content

Commit e3412d2

Browse files
committed
Improve GitHub search-facing project summary
1 parent 9786612 commit e3412d2

1 file changed

Lines changed: 5 additions & 3 deletions

File tree

‎README.md‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@
66

77
Open-source Windows 11 FIDO2/WebAuthn authenticator with TPM-backed keys, local passkeys, and TOTP.
88

9+
> **Windows 11 passkey manager and software FIDO2/WebAuthn authenticator.** Darks FIDO2 is a local-first virtual passkey provider for passwordless sign-in and TOTP/2FA, using TPM 2.0-backed keys when available.
10+
911
[![Build and test](https://github.com/darkbyte-JS/DarksFIDO2/actions/workflows/ci.yml/badge.svg)](https://github.com/darkbyte-JS/DarksFIDO2/actions/workflows/ci.yml)
1012
[![Release](https://img.shields.io/github/v/release/darkbyte-JS/DarksFIDO2?include_prereleases&label=beta)](https://github.com/darkbyte-JS/DarksFIDO2/releases)
1113
[![License](https://img.shields.io/github/license/darkbyte-JS/DarksFIDO2)](LICENSE)
@@ -14,13 +16,13 @@ Open-source Windows 11 FIDO2/WebAuthn authenticator with TPM-backed keys, local
1416
> [!WARNING]
1517
> **Experimental beta.** Current downloads are self-signed, have no SmartScreen reputation, and have not received an independent security audit. Use disposable test accounts, verify SHA-256 checksums, and read the [known limitations](docs/KNOWN-LIMITATIONS.md) before trusting a real account.
1618
17-
[Download beta](https://github.com/darkbyte-JS/DarksFIDO2/releases) · [Quick start](#quick-start) · [Security model](docs/THREAT-MODEL.md) · [Compatibility](docs/COMPATIBILITY.md) · [Report a vulnerability](https://github.com/darkbyte-JS/DarksFIDO2/security/advisories/new)
19+
[Download beta](https://github.com/darkbyte-JS/DarksFIDO2/releases) · [Quick start](#quick-start) · [Security model](docs/THREAT-MODEL.md) · [Compatibility](docs/COMPATIBILITY.md) · [Report a vulnerability](https://github.com/darkbyte-JS/DarksFIDO2/security/advisories/new)
1820

1921
![Darks FIDO2 profile screen](docs/assets/app-profile-screen.png)
2022

2123
## What it does
2224

23-
- Acts as a Windows plugin passkey manager for browser/app WebAuthn create and get requests.
25+
- Acts as a Windows 11 virtual passkey provider (software authenticator) for browser/app WebAuthn `navigator.credentials.create()` and `get()` requests.
2426
- Creates a separate non-exportable ES256 key per virtual passkey, preferring TPM 2.0 and falling back to Microsoft Software KSP.
2527
- Keeps local passkey records, TOTP seeds, TPM-key metadata, backups, and signed audit history inside independent encrypted profiles.
2628
- Supports Windows Hello and external USB/NFC/BLE authenticators through the Windows WebAuthn API.
@@ -54,7 +56,7 @@ The portable ZIP runs the manager but cannot install the packaged Windows provid
5456
| [Known limitations](docs/KNOWN-LIMITATIONS.md) | Distribution, provider, key-management, and test gaps |
5557
| [Architecture](docs/ARCHITECTURE.md) | Component/data-flow overview |
5658
| [Security policy](SECURITY.md) | Private reporting and supported versions |
57-
| [Security audit](SECURITY-AUDIT-0.6.2.md) | Focused maintainer review of CTAP CBOR and Windows WebAuthn |
59+
| [Security audit](SECURITY-AUDIT-0.6.3.md) | Focused maintainer review of CTAP CBOR and Windows WebAuthn |
5860
| [Checksums and SBOM](https://github.com/darkbyte-JS/DarksFIDO2/releases) | Per-release SHA-256 file and SPDX dependency inventory |
5961

6062
Security-sensitive behavior includes profile-bound HKDF/AES-GCM protection, PBKDF2-HMAC-SHA-256 at 600,000 iterations, DPAPI/TPM wrapping, canonical bounded CTAP2 CBOR, strict native-buffer validation, required UP/UV, local ES256 assertion verification, zeroing of unlocked key arrays, durable protected-file replacement, and transactional keyfile/install flows. See the threat model for what these controls do not protect.

0 commit comments

Comments
 (0)