Repository navigation
Bitwarden passkey vault encryption (PRF): "Error reading passkey" on the follow-up PRF read #109
Description
Activity
- added a commit that references this issue
on Sep 8, 2026 Hey, can you build firmware from develop branch and test?
Tested on the develop build (flashed 0x1050:0x0407 on RP2350-One, Windows 11, Chrome + Edge):
The bug still reproduces on real hardware. makeCredential with hmac-secret-mc succeeds — the passkey is created and stored and the "Passkey successfully created" dialog appears — but the follow-up assertion that Bitwarden issues to read the PRF key (a second user-verification prompt, the PIN prompt appears again) fails, and Bitwarden shows "Error reading passkey. Try again or uncheck this option."
So the registration-time hmac-secret-mc value and the read-back assertion value do NOT agree in this Chrome/Windows→key path, even though the new conformance cases pass in CI. The difference must be in what this specific client stack sends for the read ceremony (salt layout, UV handling, or something on the Windows WebAuthn bridge). I can run any diagnostic build or provide USB logs if helpful.

- Tested on the develop build (flashed 0x1050:0x0407 on RP2350-One, Windows 11, Chrome + Edge): The bug still reproduces on real hardware. makeCredential with hmac-secret-mc succeeds — the passkey is created and stored and the "Passkey successfully created" dialog appears — but the follow-up assertion that Bitwarden issues to read the PRF key (a second user-verification prompt, the PIN prompt appears again) fails, and Bitwarden shows "Error reading passkey. Try again or uncheck this option." So the registration-time hmac-secret-mc value and the read-back assertion value do NOT agree in this Chrome/Windows→key path, even though the new conformance cases pass in CI. The difference must be in what this specific client stack sends for the read ceremony (salt layout, UV handling, or something on the Windows WebAuthn bridge). I can run any diagnostic build or provide USB logs if helpful. [image: image.png] ср, 9 сент. 2026 г. в 06:00, MaxMur ***@***.***>:…*TheMaxMur* left a comment (TheMaxMur/RS-Key#109) <#109 (comment)> Hey, can you build firmware from develop branch and test? — Reply to this email directly, view it on GitHub <#109?email_source=notifications&email_token=AS2W2ZTLDVSD5B6RKQT7F435OCMRHA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKNJZGM3DCOJQGYYKM4TFMFZW63VGMF2XI2DPOKSWK5TFNZ2KYZTPN52GK4S7MNWGSY3L#issuecomment-5593619060>, or unsubscribe <https://github.com/notifications/unsubscribe-auth/AS2W2ZVBOETFWPPBULL25NT5OCMRHAVCNFSNUABGKJSXA33TNF2G64TZHMYTENRWGQ3DSOJVHE5US43TOVSTWNJTGY2TANBRGU3TJILWAI> . Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS <https://github.com/notifications/mobile/ios/AS2W2ZWXQ5ZEODGHBBCPUQ35OCMRHA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKNJZGM3DCOJQGYYKM4TFMFZW63VGMF2XI2DPOKSWK5TFNZ2KUZTPN52GK4S7NFXXG> and Android <https://github.com/notifications/mobile/android/AS2W2ZTC3IS3ZWFFTZXOXGL5OCMRHA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKNJZGM3DCOJQGYYKM4TFMFZW63VGMF2XI2DPOKSWK5TFNZ2K4ZTPN52GK4S7MFXGI4TPNFSA>. Download it today! You are receiving this because you authored the thread.Message ID: <TheMaxMur/RS-Key/issues/109/5593619060 ***@***.***>
Hi, I ordered a YubiKey with firmware version 5.8.0, it supports PRF, and I’ll take a closer look at your issue this weekend.
- added 4 commits that reference this issue
on Sep 15, 2026 Hey, can you build firmware from develop branch and test?
Reacted by Alximik501Confirmed — the bug is not in the firmware, it's a Windows 10 limitation.
On this same RS-Key (develop build) and the same Chrome/Edge versions, the exact same registration flow works first try on Windows 11: passkey created with "Use for vault encryption" checked, no error, vault unlocked by the key.
On Windows 10 (build 19045), every browser fails at the follow-up PRF read. The WebAuthn PRF extension needs the Windows WebAuthn API's WEBAUTHN_API_VERSION_8 / hmac-secret support, which only ships with Windows 11 25H2 + the Feb 2026 cumulative update (KB5077181). Windows 10 has none of it — Chrome 153 and Edge 153 on Win10 cannot carry the PRF read either way, regardless of what the authenticator answers.
So this is a client-OS gap, not an RS-Key defect. The key, firmware v0.4.10/develop with hmac-secret + hmac-secret-mc, works correctly with a PRF-capable platform. Thanks for the help — and it was a useful exercise: your new conformance case covering the registration-vs-read PRF equality is good to have either way.
Closing note for anyone else: vault-encryption passkeys on RS-Key need Windows 11 25H2+, macOS 15+, or Android/Chrome.
Reacted by MaxMurReacted by Alximik501
Before filing
main.Area
FIDO2 / U2F / passkeys / ssh-sk
Firmware build
v0.4.10 (
81d8c8cb),VIDPID=Yubikey5build (0x1050:0x0407, YubiKey 5.7.4-compatible identity) — also reproduced on the v0.4.5-era build, so not a recent regression.Board
Waveshare RP2350-One (no display), flashed via BOOTSEL drag-and-drop.
Host environment
Windows 10 desktop, Chrome and Edge (both Chromium), Bitwarden web vault. FIDO PIN is set on the key.
What happened
Bitwarden "Log in with passkey" → register a new passkey with the "Use for vault encryption" checkbox (WebAuthn PRF). The passkey is created successfully (makeCredential with
hmac-secret-mc/PRF appears to work — the "Passkey successfully created" dialog appears and the credential is stored on the key, visible inykman fido credentials list), but then Bitwarden performs its follow-up read of the PRF key (a second user-verification prompt, as documented: "we request an assertion from the authenticator, which will provide the key") and fails with:Steps to reproduce
Expected vs actual
Expected: PRF output read succeeds, passkey saved with vault-encryption enabled (this works with a genuine YubiKey 5).
Actual: the second (read) WebAuthn ceremony fails after user verification; the passkey is left on the key but Bitwarden cannot use it for decryption.
Notes / hypothesis
authenticatorGetInfoadvertiseshmac-secretandhmac-secret-mc; registration-time hmac-secret evaluation succeeds.saltAuthsize, or UV-flag handling between makeCredential-mc and getAssertion) versus what a real YubiKey answers.Output / logs
Anything else
No response