Live data from Hacker News

SQRL - Replacement for usernames and passwords

grc.com

1–10 of 138 posts

Re: SQRL - Replacement for usernames and passwords

#4
post #3

How does this compare to OpenID? Seems similar except with the premise that a user is their own identity provider, which is a QR-code-reading app on their smartphone. I like!

> How does this compare to OpenID?

It's completely different. You don't need to remember an url, you don't need to remember a password, there is no third party involved in the authentication process, ... I could go on, but it's really a completely different authentication mechanism.

Re: SQRL - Replacement for usernames and passwords

#7
post #5

How is this better than any other phone-based 2-factor auth scheme?

Well, it's not really 2-factor is it? It's just the phone part of a 2-factor login and no web form part. Presumably the screen shot that showed a login form was for people without the phone app.

Re: SQRL - Replacement for usernames and passwords

#8
post #5

How is this better than any other phone-based 2-factor auth scheme?

It's not - it's really just a password manager. The "something I know and something I have" is completely removed by only requiring you to have the phone. If it's a password manager, then that is what it is; if it's meant for security, then it comes back to the recent article on fingerprints not being a password.

Re: SQRL - Replacement for usernames and passwords

#9
Interesting - so you generate a key pair on your phone (this is your identity and can be backed up to a printable QR code). Then, to login to any site, you scan a QR code displayed beside a login form and your phone can verify it''s identity (i.e. proves that it's the holder of the key pair). Perhaps on the first sign-in, the site will ask for an email address or some details to create an account for you.
Post reply on HN