> (it's not an issue with Firefox's implementation. This can be demonstrated by spoofing the useragent as a Chromium-based browser and attempting the same login flow […]).
> (it's not an issue with Firefox's implementation. This can be demonstrated by spoofing the useragent as a Chromium-based browser and attempting the same login flow […]).
In fact it's not completely unlikely that that is what happened here. Firefox still has incomplete support for the web authentication API [1], and in particular FIDO2 devices did not work if a PIN is set until Firefox 114 - only a few months ago! I'm not sure if this could be related, but Firefox also still does not support passkeys [2], so I'm sure someone will get blamed for anti-competitive behavior for that at some point.
If Microsoft solves the issue within the next 30 days, I will consider that you were right.
"30 days" is an arbitrary extension of the timeline for something that was reported 4 months ago to Microsoft, and should have been already fixed.
That check lies somewhere along the line between "having the direct goal of breaking authentication flow (pure malice)" and "is a completely legitimate programming error (pure incompetence)."
I am not ready to assume pure incompetence (and here's where I might be wrong).