A bank deploys FIDO2 authentication but their legacy mobile app only supports SMS OTP. Which migration strategy best maintains backward compatibility while advancing security?
-
A
Disable SMS OTP immediately and force FIDO2 enrollment
-
B
Run SMS OTP and FIDO2 in parallel, letting users opt into FIDO2 progressively
-
C
Replace SMS OTP with TOTP apps as an intermediate step before FIDO2
-
D
Deploy FIDO2 only for new accounts and keep SMS OTP for existing users forever