Summary

  • "Setting up 2FA with Passkey" is a section heading in RIPE NCC's two-step verification support documentation, not a Taiwanese organisation; the directory tag is a classification artifact of ISO 3166-1 country tagging, not publisher attribution.
  • RIPE NCC made 2FA mandatory on RIPE NCC Access accounts on 27 March 2024 and added passkeys as a second factor on 30 May 2024, stored on FIDO2 hardware keys or in password managers, supported on iOS, Android and most desktop browsers.
  • The enrollment flow under that heading is mechanical and short: click Passkey, register the credential, choose where to save it, name it, then copy the recovery codes shown on screen and store them safely.

The documented flow sits inside RIPE NCC's two-step verification page, which states that "Two-factor authentication (2FA) is a mandatory security feature that adds an extra layer of protection to your RIPE NCC Access account" and describes the two permitted methods — an authenticator application or a passkey, either software or hardware. RIPE NCC Access is the single sign-on system used for the LIR Portal, RPKI and other RIPE NCC services, which means the passkey flow protects credentials that administer internet number resources, not consumer accounts at any Taiwanese provider (two-step verification documentation).

The mandate arrived in stages. RIPE NCC announced that 2FA would become mandatory on RIPE NCC Access accounts on Wednesday 27 March 2024, with accounts lacking 2FA prompted at login to follow an emailed setup link (mandatory 2FA announcement). Two months later, on 30 May 2024, it announced passkeys as an additional method: passkeys can be stored on a FIDO2-compatible hardware security key or in a password manager, potentially synced across devices, and are supported on mobile devices and most desktop browsers. The announcement attributed the addition to member requests for security keys (passkey announcement).

Under the heading "Setting up 2FA with Passkey", the enrollment flow is: click "Passkey" on the setup screen, follow the instructions to register the passkey, choose where to save it, give it a name, then copy the recovery codes shown on the setup screen and store them safely. Recovery codes are the documented fallback when a user deletes the authenticator app, has an empty phone battery, loses the phone, or otherwise cannot generate a security code.

The supported authenticators are WebAuthn/FIDO2 devices; RIPE NCC Access runs on Keycloak, which supports options including YubiKey, SoloKeys, Google Titan Security Key, Windows Hello and Apple Face ID/Touch ID in modern browsers.

The platform behind the feature is as informative as the feature itself. According to a RIPE Labs account by Felipe Victolla Silveira, RIPE NCC's earlier Atlassian Crowd backend "lacked support for modern Two-Factor Authentication (2FA) methods like FIDO2 keys, as well as secure integration methods such as SAML 2.0 and OIDC". RIPE NCC replaced it with Keycloak, completed in July 2023 on a container orchestration platform using cloud infrastructure (EKS in AWS); 2FA then moved to Keycloak's native implementation, which made mandatory 2FA and passkey support possible (RIPE Labs account).

The mandate is now codified. RIPE-843, the RIPE NCC Access SSO Account Authentication and Security Key Management Policy effective May 2025, states that it is mandatory to enable two-factor authentication on an SSO account, set up using a time-based one-time password or hardware/software passkeys, applying to all RIPE NCC Access account holders, including LIR Portal users managing IP resources and RPKI (RIPE-843).

The UK National Cyber Security Centre's assessment gives the security rationale independent of the registry: FIDO2 credentials, including passkeys, are as secure or more secure than traditional MFA against all common credential attacks observed in the wild, while SMS, email codes, app TOTP and push approvals remain inherently phishable. NCSC also stresses that services should give users clear ways to manage and remove credentials and set up recovery options (NCSC guidance).

Why, then, does the directory tag read "Taiwan"? RIPE NCC's own records supply the answer. In August 2024, Managing Director and CEO Hans Petter Holen replied to a 3 May 2024 letter from Ms. Hsin-Hsin Chen of the Taipei Representative Office, writing that the registry is "aware of concerns of the designation of Taiwan in our member directory" and does not make determinations about the names or status of countries; it assigns country codes to resource holders using the internationally recognised ISO 3166-1 list, to remain neutral and consistent across its 76-country service region (RIPE NCC response). The NRO's country-code table carries the row "TAIWAN, PROVINCE OF CHINA | TW | TWN | APNIC", placing Taiwan in the APNIC service region (NRO list), and RIPE NCC's List of Members states that inclusion of country names should not be interpreted as an endorsement or position on the international status of any country or territory (List of Members). The disagreement was live in the community too: an April 2024 cooperation-wg thread opened by Taiwan-based user Tsung-Yi Yu objected to the listing, with participants noting the name derives from ISO/UN sources, not from RIPE (cooperation-wg thread).

The conclusion follows directly: the directory card's "Setting up 2FA with Passkey" is a heading lifted from a page published by a Netherlands-based registry, and its TW classification inherits ISO 3166-1 tagging rather than publisher attribution. The object beneath the mislabel is a real and consequential identity system for internet number resource administration.