NFC WebAuthn: evaluate token2-fido-bridge as a PC/SC to USB-HID shim #2
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tay/src#2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
Desktop Firefox cannot use an NFC-presented FIDO2 authenticator for WebAuthn.
USB works fine; tapping the same key on the contactless reader does nothing.
This is a Firefox limitation, not a local misconfiguration. Firefox's CTAP2
transport is USB-HID only:
libxul.socontains zero PC/SC symbols (SCardEstablishContext,winscard,pcscliteall absent)hidrawreference sits next to thehidiocgrdescsize()LinuxHID ioctl and the string
Unable to find deviceChromium has the same limitation on Linux. NFC FIDO2 is effectively a mobile
feature, where the OS owns the NFC stack and brokers it to the browser.
Loading
opensc-pkcs11.sounder Settings > Privacy & Security > SecurityDevices does not help. PKCS#11 and WebAuthn are separate code paths in
Firefox: PKCS#11 covers client certificates and S/MIME (and does work over
NFC), but
navigator.credentials.get()never consults it.Candidate solution
https://github.com/token2/token2-fido-bridge
Rather than patching the browser, it presents a virtual USB-HID FIDO
authenticator through
/dev/uhid, translates CTAP-HID frames into ISO 7816APDUs, and relays them to the card over PC/SC. Firefox sees an ordinary USB
HID key and never knows NFC is involved.
Vendor-neutral by design: it speaks standard CTAP2/ISO7816 and is documented
to work with any FIDO2 authenticator visible to PC/SC, not just Token2
hardware. C++, single ~250 KB binary, depends only on
libpcsclite.There is an earlier Python implementation of the same idea at
https://github.com/BryanJacobs/fido2-hid-bridge — larger footprint, but worth
comparing if the C++ one proves troublesome.
Prerequisites already satisfied on basedbox
Confirmed working as of system generation 14:
/dev/uhidpresent;CONFIG_UHID=manduhid.koloaded (kernel 7.1.8)pcscdrunning viapcscd-service-typeAlcor Link AK9567 [Contactless Card Reader]Work required
~/reference/external_src/and review the source. It is a0.1.0 release, it runs as root for
/dev/uhid, and it relays every CTAPexchange between browser and authenticator. That trust boundary deserves
a read before it goes anywhere near a real credential.
cmake-build-system,pcsc-liteinput). Not currently packaged in Guix; neither is the Python variant.
config-k8-plus.scm.packaging/70-token2-fido-bridge.rulesviaudev-rules-service.been tested on Ubuntu with Chromium and Snap Firefox, so this
combination is unproven. The README's
snap connect firefox:u2f-devicesstep does not apply here.
Not blocking
USB WebAuthn already works. This is a convenience improvement, so there is no
urgency and no reason to rush the security review.
Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-20T06:18:47Z.