WebAuthn virtual authenticator UV behavior diverges from platform authenticator modalities
24K reputation · 07 Jul 2020, 19:47 UTC
Supported feature
Chrome's WebAuthn Virtual Authenticator API via CDP enables automated passkey testing without physical security keys. The WebAuthn.addVirtualAuthenticator command creates a virtual authenticator with configurable hasUserVerification and hasResidentKey options.
What needs diagnosis
When hasUserVerification=true and WebAuthn.setUserVerified(true) is called, the virtual authenticator always reports the UV flag as true in assertions. However, it does not enforce platform-specific UV modalities (Windows Hello PIN, Touch ID, Android biometric) or replicate hardware-enforced UV retry limits and lockout behaviors. The User Presence (UP) flag is also always reported as true with no CDP command to toggle it independently.
This creates a gap for relying parties that branch logic on authenticatorAttachment (platform vs cross-platform) or implement UV retry policies. Credential storage remains ephemeral and in-memory, unlike platform authenticators that persist via cloud sync.
Specific questions
- Can the virtual authenticator be configured to simulate platform-specific UV modalities and their associated retry counters?
- Is there a CDP mechanism to toggle the UP flag independently of UV for testing UP-only scenarios?
- Does the WebAuthn Level 3 spec define extension points for UV modality and retry behavior that Chrome's implementation could expose?