
內容簡介
Bye Bye Passwords 外掛透過 WebAuthn/Passkeys 技術為 WordPress 提供現代化的無密碼身份驗證,讓使用者可以安全且方便地使用生物識別、安保金鑰或平台驗證器登入,徹底告別弱密碼的困擾。
【主要功能】
• 無密碼登入:使用 Touch ID、Face ID、Windows Hello 或安保金鑰登入
• 多重 Passkeys:註冊多個設備以便隨時存取
• 備援碼生成:產生一次性備援碼以備不時之需
• 增強安全性:完全消除基於密碼的攻擊
• 使用者友好:簡單設置,無需技術知識
• 隱私保護:身份驗證資料保留在伺服器上
外掛標籤
開發者團隊
原文外掛簡介
Bye Bye Passwords brings modern passwordless authentication to WordPress using WebAuthn/Passkeys technology. Say goodbye to weak passwords and hello to secure, convenient login with biometrics, security keys, or platform authenticators.
Key Features
Passwordless Login – Sign in using Touch ID, Face ID, Windows Hello, or security keys
Multiple Passkeys – Register multiple devices for convenient access anywhere
Recovery Codes – Generate one-time backup codes for emergency access
Enhanced Security – Eliminate password-based attacks completely
User-Friendly – Simple setup with no technical knowledge required
Privacy-Focused – Your authentication data stays on your server
WordPress Integration – Seamlessly integrated into WordPress admin and login
How It Works
Register a passkey from your WordPress admin profile
Use your device’s built-in authentication (fingerprint, face, PIN)
Sign in instantly without typing passwords
Requirements
SSL/HTTPS enabled website (required for WebAuthn)
Modern browser with WebAuthn support
PHP 8.0 or higher
WordPress 5.0 or higher
External Services
This plugin may connect to the FIDO Alliance Metadata Service (MDS) to download root certificates for authenticator validation.
FIDO Alliance Metadata Service
URL: https://mds.fidoalliance.org/
Purpose: Downloads attestation root certificates to verify the authenticity of security keys and passkey devices
When: Only when attestation verification is enabled and the plugin needs to update its certificate store (not during normal authentication)
Data sent: No personal or user data is transmitted – only a standard HTTP GET request
Service provider: FIDO Alliance
Terms of Use: https://fidoalliance.org/metadata/
Privacy Policy: https://fidoalliance.org/privacy-policy/
No user data, credentials, or personal information is ever sent to external services. All authentication happens locally on your server.
