Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

WebAuthn with Touch ID and Attestation not working on ARM Macs (Safari)

I found this issue when I tried to enroll my fingerprint on the Yubico demo site (https://demo.yubico.com/webauthn-technical/registration) with Safari:


I then tried other browsers like Google Chrome and Microsoft Edge, they all worked.


Upon further testing with the website https://webauthn.io (which gives more options to test), I found that if I let "Attestation Type" to be "None", the registration will success, but if it was set to "Direct" or "Indirect", the registration fails. Yubico demo site uses Attestation by default (to detect YubiKey model), which explains why it's failing.


WebKit should work with Attestation, as this blogpost https://webkit.org/blog/11312/meet-face-id-and-touch-id-for-the-web/ said:

Attestation is an optional feature which provides websites a cryptographic proof of the authenticator’s provenance such that websites that are restricted by special regulations can make a trust decision. Face ID and Touch ID for the web offers Apple Anonymous Attestation. Once verified, this attestation guarantees that an authentic Apple device performed the WebAuthn registration ceremony, but it does not guarantee the operating system running on that device is untampered.


Some other users of Macs with Apple Chip have also encountered this problem. However one of my friend that uses Mac with x86 Processor (and Apple T2 Security Chip) didn't encounter this issue.


This issue prevents the registration of Touch ID on certain websites, Dropbox 2FA for example. Does anyone have a solution or workaround?



MacBook Pro 13″, macOS 12.1

Posted on Jan 27, 2022 7:48 PM

Reply
Question marked as Best reply

Posted on Feb 18, 2022 8:17 AM

Extrawdw wrote:

I found this issue when I tried to enroll my fingerprint on the Yubico demo site (https://demo.yubico.com/webauthn-technical/registration) with Safari:


https://discussions.apple.com/content/attachment/7351756e-5b51-4cb2-94d1-27e24e48a353
I then tried other browsers like Google Chrome and Microsoft Edge, they all worked.

....

Some other users of Macs with Apple Chip have also encountered this problem. However one of my friend that uses Mac with x86 Processor (and Apple T2 Security Chip) didn't encounter this issue.

This issue prevents the registration of Touch ID on certain websites, Dropbox 2FA for example. Does anyone have a solution or workaround?




Try making some changes —


Safari>Preferences>Privacy

Safari>Preferences>Security

Safari>Preferences>Passwords

Safari>Preferences>Websites



and compare your results...



if no insight or resolve— refer to the developers website; Support/Help/FAQ/known issues/compatibility:

Contact a third party vendor

Contact a third-party vendor - Apple Support


see:

https://support.yubico.com/hc/en-us






you can always Call Customer Support (800) MY–APPLE (800–692–7753)

or on line Apple Support


Outside the USA—Contact Apple for support and service by phone

See a list of Apple phone numbers around the world.

Contact Apple for support and service - Apple Support


Similar questions

1 reply
Question marked as Best reply

Feb 18, 2022 8:17 AM in response to Extrawdw

Extrawdw wrote:

I found this issue when I tried to enroll my fingerprint on the Yubico demo site (https://demo.yubico.com/webauthn-technical/registration) with Safari:


https://discussions.apple.com/content/attachment/7351756e-5b51-4cb2-94d1-27e24e48a353
I then tried other browsers like Google Chrome and Microsoft Edge, they all worked.

....

Some other users of Macs with Apple Chip have also encountered this problem. However one of my friend that uses Mac with x86 Processor (and Apple T2 Security Chip) didn't encounter this issue.

This issue prevents the registration of Touch ID on certain websites, Dropbox 2FA for example. Does anyone have a solution or workaround?




Try making some changes —


Safari>Preferences>Privacy

Safari>Preferences>Security

Safari>Preferences>Passwords

Safari>Preferences>Websites



and compare your results...



if no insight or resolve— refer to the developers website; Support/Help/FAQ/known issues/compatibility:

Contact a third party vendor

Contact a third-party vendor - Apple Support


see:

https://support.yubico.com/hc/en-us






you can always Call Customer Support (800) MY–APPLE (800–692–7753)

or on line Apple Support


Outside the USA—Contact Apple for support and service by phone

See a list of Apple phone numbers around the world.

Contact Apple for support and service - Apple Support


WebAuthn with Touch ID and Attestation not working on ARM Macs (Safari)

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.