CTAP1/U2F-only authenticators should not be used for CTAP2-only operations
@micolous is already working on this.
Since Aug 13, 2026.
Assessment
This issue has not been assessed yet.
Description
Firefox bug: https://bugzilla.mozilla.org/show_bug.cgi?id=2063494
Related to #367, possible repeat of #72.
When selecting devices, authenticator-rs offers to use CTAP1/U2F-only devices with register() and sign() operations that can only work with CTAP2 (eg: uv = required or rk = required).
The operation also immediately fails when:
- there is exactly one authenticator during initial enumeration, which only supports CTAP1
- there are no authenticators connected during initial enumeration, and then a CTAP1 authenticator is connected
Example with ctap2.rs, patched to set uv = required, with a CTAP1-only authenticator:
[2026-08-13T23:34:27Z INFO authenticator::transport::platform::device] new device "/dev/hidraw2"
[2026-08-13T23:34:27Z DEBUG authenticator::transport::hid] sent to Device "/dev/hidraw2" cmd=Init: [233, 42, 79, 48, 49, 104, 111, 16]
[2026-08-13T23:34:27Z DEBUG authenticator::transport::hid] got from Device "/dev/hidraw2" status=Init: [233, 42, 79, 48, 49, 104, 111, 16, 0, 29, 0, 2, 2, 4, 3, 5, 1]
[2026-08-13T23:34:27Z DEBUG authenticator::transport::platform::monitor] get_property_linux Querying property Manufacturer from /sys/devices/pci0000:00/0000:00:14.0/usb3/3-6/3-6:1.0/0003:1050:0402.000C/hidraw/hidraw2
[2026-08-13T23:34:27Z DEBUG authenticator::transport::platform::monitor] get_property_linux Querying property Product from /sys/devices/pci0000:00/0000:00:14.0/usb3/3-6/3-6:1.0/0003:1050:0402.000C/hidraw/hidraw2
[2026-08-13T23:34:27Z DEBUG authenticator::transport::hid] "/dev/hidraw2": U2FDeviceInfo { vendor_name: [85, 110, 107, 110, 111, 119, 110, 32, 86, 101, 110, 100, 111, 114], device_name: [85, 110, 107, 110, 111, 119, 110, 32, 68, 101, 118, 105, 99, 101], version_interface: 2, version_major: 4, version_minor: 3, version_build: 5, cap_flags: WINK }
[2026-08-13T23:34:27Z DEBUG authenticator::transport::hid] sending GetVersion to Device { path: "/dev/hidraw2", fd: File { fd: 3, path: "/dev/hidraw2", read: true, write: true }, in_rpt_size: 64, out_rpt_size: 64, cid: [0, 29, 0, 2], dev_info: Some(U2FDeviceInfo { vendor_name: [85, 110, 107, 110, 111, 119, 110, 32, 86, 101, 110, 100, 111, 114], device_name: [85, 110, 107, 110, 111, 119, 110, 32, 68, 101, 118, 105, 99, 101], version_interface: 2, version_major: 4, version_minor: 3, version_build: 5, cap_flags: WINK }), secret: None, authenticator_info: None, protocol: CTAP1 }
[2026-08-13T23:34:27Z DEBUG authenticator::transport::hid] sent to Device "/dev/hidraw2" cmd=Msg: [0, 3, 0, 0, 0, 0, 0]
[2026-08-13T23:34:27Z DEBUG authenticator::transport::hid] got from Device "/dev/hidraw2" status=Msg: [85, 50, 70, 95, 86, 50, 144, 0]
[2026-08-13T23:34:27Z INFO authenticator::statemachine] Device "/dev/hidraw2" continues with the register process
thread 'main' panicked at examples/ctap2.rs:219:23:
Registration failed: UnsupportedOption(UserVerification)
note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
[2026-08-13T23:34:27Z INFO authenticator::statemachine] Statemachine was cancelled. Cancelling transaction now.
[2026-08-13T23:34:27Z INFO authenticator::transport::platform::transaction] Transaction was cancelled.
Instead, these devices should be ignored, and authenticator-rs should wait for a CTAP2 connector to be connected.
U2F authenticators that do not have a button will fake user presence on any request issued within a few seconds of the device being plugged in (eg: Nitrokey U2F). Even if there are multiple authenticators connected, they will capture a CTAP2-only request, without the option to use a CTAP2 authenticator.
Also, when issuing a CTAP2-only requests with use_ctap1_fallback = true, the library waits for an authenticator to be selected before rejecting it. Instead, the request should be immediately rejected without waiting for an authenticator to be connected.
These issues are reproducible with Firefox Nightly on Linux.
- Dominant language
- Rust
- Stars
- 316
- Forks
- 82
- Avg merge
- 4d 20h
- Merged PRs (30d)
- 1
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from mozilla/authenticator-rs
-
Difficulty 1/5 Under an hour Newbie friendliness 68/100
mozilla/authenticator-rs#347 ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 48/100
mozilla/authenticator-rs#376 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 52/100
mozilla/authenticator-rs#375 · 1 comment ·
-
bug
mozilla/authenticator-rs#373 · 1 assignee ·
-
mozilla/authenticator-rs#367 · 1 assignee ·
All issues in mozilla/authenticator-rs
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
kwakseongjae/auto-hwp#319 ·
-
area:cli bug filter-quality good first issue priority:medium
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
Difficulty 1/5 Under an hour Newbie friendliness 72/100
bevyengine/bevy#25861 ·
-
comp-datalake
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
ClickHouse/ClickHouse#121222 ·
-
enhancement remote
Difficulty 2/5 1-3 hours Newbie friendliness 68/100