How is this better than any other phone-based 2-factor auth scheme?
It's not - it's really just a password manager. The "something I know and something I have" is completely removed by only requiring you to have the phone. If it's a password manager, then that is what it is; if it's meant for security, then it comes back to the recent article on fingerprints not being a password.
SQRL - Replacement for usernames and passwords
11–20 of 138 posts
Re: SQRL - Replacement for usernames and passwords
#12How is this better than any other phone-based 2-factor auth scheme?
Well, it's not really 2-factor is it? It's just the phone part of a 2-factor login and no web form part. Presumably the screen shot that showed a login form was for people without the phone app.
Re: SQRL - Replacement for usernames and passwords
#13Not exactly a new idea. Here is some prior art http://openaccess.uoc.edu/webapps/o2/bitstream/10609/14761/6... http://www.computer.org/csdl/proceedings/ares/2009/3564/00/3... As far as I know, QR-TAN is being used in Germany for authentication by a number of banks.
So then they pulled it, told us something better was coming and nearly two years later, nothing.
Re: SQRL - Replacement for usernames and passwords
#14How is this better than any other phone-based 2-factor auth scheme?
It's 1 step. Just scan a code. Con: requires internet connectivity, unlike some 2-factor implementations
Re: SQRL - Replacement for usernames and passwords
#15How is this better than any other phone-based 2-factor auth scheme?
He spends a good chunk of the latest episode of Security Now [1] describing it's advantages over current schemes. The episode isn't up yet (I listened to it on the the site's live stream), but it should be soon.
Re: SQRL - Replacement for usernames and passwords
#16The authentication should be safe to be transmitted on the same network... What about if the phone and computer are on the same (i.e. WiFi) network?
Re: SQRL - Replacement for usernames and passwords
#17How is this better than any other phone-based 2-factor auth scheme?
It's not - it's really just a password manager. The "something I know and something I have" is completely removed by only requiring you to have the phone. If it's a password manager, then that is what it is; if it's meant for security, then it comes back to the recent article on fingerprints not being a password.
I've wondered about the "something I know" dimension as well. Perhaps a passphrase could be used (it already is used to secure the master key). It'd still be a major improvement, as only your local device would need it, and you wouldn't have to have a separate password for each site.
Re: SQRL - Replacement for usernames and passwords
#18> Steve Gibson is somewhat of a "fringe" charlatan. In some professional security circles, he is not considered a reputable security professional, rather more of a snake oil salesman peddling third-rate software with bold claims. While many of his claims are a bit outlandish or bold, few, if any, are demonstrably false. However, when asked to speak on security topics, Gibson is getting adept at putting his foot in his mouth. A single amusing quote may be laughable, but a series of them begin to paint a picture of someone who doesn't really understand security. Rather, he seems to know enough buzzwords and ideas to be dangerous to his clients.
Re: SQRL - Replacement for usernames and passwords
#19http://attrition.org/errata/charlatan/steve_gibson/ > Steve Gibson is somewhat of a "fringe" charlatan. In some professional security circles, he is not considered a reputable security professional, rather more of a snake oil salesman peddling third-rate software with bold claims. While many of his claims are a bit outlandish or bold, few, if any, are demonstrably false. However, when asked to speak on security topic…
Re: SQRL - Replacement for usernames and passwords
#20Not exactly a new idea. Here is some prior art http://openaccess.uoc.edu/webapps/o2/bitstream/10609/14761/6... http://www.computer.org/csdl/proceedings/ares/2009/3564/00/3... As far as I know, QR-TAN is being used in Germany for authentication by a number of banks.