Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Nitrokey Passkey Welcome Page #360

Open
daringer opened this issue Dec 14, 2024 · 0 comments
Open

Nitrokey Passkey Welcome Page #360

daringer opened this issue Dec 14, 2024 · 0 comments
Labels
top top prio top+

Comments

@daringer
Copy link
Contributor

daringer commented Dec 14, 2024

The NK Passkey documentation is bad! This is the entry product into the world of hardware tokens - we should restructure the page to be welcoming and guiding a (potentially inexperienced and/or to-be) customer on how to increase their personal security using a NK Passkey aka FIDO2 device.

I'd suggest roughly the following structure of this page - there are a lot of topics, key will be to handle much w/o too much complexity and giving proper and many links for more details.

Introduction

  • What is the Nitrokey Passkey?
  • Why you should care about hardware security keys
  • Basic benefits (security, convenience, privacy)

Getting Started

  • What's in the box (image with labeled led + touch "button")
  • introduce the "user presence" concept in 1-2 lines
  • First-time plug in (what to expect tabbed win/linux/mac) - not much happens, but something does...
  • Basic device management through native tooling (windows: settings, linux/mac: browser)
    • combine with: "set pin for your nitrokey passkey"

How It Makes Your Life More Secure (keep it simple, avoid being too technical)

  • Simple explanation of FIDO2/WebAuthn (further reading (our fido2 article)) otherwise skip u2f/passkey/fido2 details)
  • Example use-cases: website login, desktop login, ssh (linked)

Using Your Passkey

  • hands on! Increase your personal security now!
  • example registration & login for some website(s)
    • maybe for some very common (2-3?) services (ms, google, ...) explicit guides:
      • with links (assuming the user is already logged in)
      • and step by step instructions

Lost Device / Backup / Recovery

  • explain possible scenario: device unavailable/lost etc
  • basic recommended backup: 2nd/multiple device(s), all must be registered, too
  • explain some other typical recovery methods: recovery codes, other 2fa methods (otp, sms, email)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
top top prio top+
Projects
None yet
Development

No branches or pull requests

1 participant