MFA | Add support for Yubikey
Please can you add support for Yubikeys, the development webpage is here:
Thanks for sharing with us here, everyone. We appreciate why you'd like simpler methods to improve efficiency when logging in to use Xero.
Our product team have started some work to enable logging into Xero using passkeys. As mentioned in some of your comments, this'll support Yubikeys by default.
For now, we'll move this idea to Under review and I'll come back to keep you updated on the latest news for this feature.
-
Gabriel Brady
commented
This absolutely positively boggles the mind... Xero is slipping. Xero used to be innovative and first to market... those days are long gone...
At least Xero doesn't support SMS based 2FA like some of the major banks...
It was officially deprecated by NIST in 2016....
https://www.schneier.com/blog/archives/2016/08/nist_is_no_long.html
Get with it Xero, the world is moving to passkeys...
Security is a bare minimum requirement. It is a necessary but not sufficient condition. Without security there is no value to anything else you do...
This is what happens when management starts to become non-technical...
-
Pablo Maurin
commented
+1
I'm a new Xero user. I selected the product because of the automated bank feeds, invoicing, and what looks like an effort to allow external developers (https://developer.xero.com/) building tools that interact with it.
I am shocked to learn that the best Xero can do for security is just an authenticator app.
I would like the accounting system that is essential for managing ALL of my company financials, and literally moving money in and out of my accounts to be protected by modern security best practices. In this case Hardware keys and passkeys.
-
Jonathan Greene
commented
Xero, celebrating 329 days of Yubikey feature review!
-
Ben Moran
commented
+1
-
Kristen Zwarts
commented
Any ETA on this?
-
Sawan Patel
commented
Please enable support for hardware security keys
-
Tracy Phua
commented
ETA please
-
Josh De Raadt
commented
Everyone voting for this should also vote for SSO. Crazy that they're happy to increase price without one acceptable login method that meets cybersecurity requirements in Australia. I have customers looking to move away from Xero for these features.
-
Jonathan Greene
commented
+245 days later... no Yubikey support. Yubikey without a passkey please.
-
Jason Loeken
commented
Please provide an ETA for this.
-
Jonathan Greene
commented
Is there an ETA for YubiKey support?
-
Jonathan Greene
commented
There is a distinction between using a YubiKey and a Using a Yubikey with a passkey. I request YubiKey ONLY.
Passkeys add friction and the YubiKey request is to REDUCE friction.
Also, please support multiple Yubikeys per user.
-
Josh De Raadt
commented
If not offering SSO, this is essential.
-
Andrew Richards
commented
It's now 8 months since you moved this to "Under review". How long will it take to review something so critical as modern security?
-
Tim Burne
commented
Hi, any updates on this?
-
Kirsten Crutchley
commented
Second all comments below, this is an essential addition.
-
Jason Loeken
commented
Please Add Fido2 authentication as this will speed up MFA and 2FA auth.
it will work on phones via NFC contact of the key to your phone and with workstations you need to tap the sensor. we use it for all our other security MFA applications.
- Faster to log in
- Most secureFIDO2 is the best...
-
John Crane
commented
A core driver for cyber criminals is to steal money. It should be a standard offering to have a hardware based, phishing resistant authenticator like Yubikey on a financial system. Please take this seriously Xero.
-
Ben Curthoys
commented
I just got a pair of Yubikeys because AWS was nagging me constantly for MFA and I worry about losing my phone.
Did not occur to me to check in advance whether Xero would support Yubikey, I just assumed it would, and I'm honestly shocked and a bit embarrassed for you that you don't.
-
Iain Elder
commented
Just started using Xero.
Every time I log in it wants me to set up MFA.
Yubikey is my preferred option here.