Live data from Hacker News

SQRL - Replacement for usernames and passwords

grc.com

11–20 of 138 posts

Re: SQRL - Replacement for usernames and passwords

#11
post #5

How is this better than any other phone-based 2-factor auth scheme?

It's not - it's really just a password manager. The "something I know and something I have" is completely removed by only requiring you to have the phone. If it's a password manager, then that is what it is; if it's meant for security, then it comes back to the recent article on fingerprints not being a password.

I dunno about the fingerprints analogy, that's still more boneheaded -- I mean, I can change digital secrets a lot easier than I can change my fingerprints ;-)

Re: SQRL - Replacement for usernames and passwords

#12
post #5

How is this better than any other phone-based 2-factor auth scheme?

Well, it's not really 2-factor is it? It's just the phone part of a 2-factor login and no web form part. Presumably the screen shot that showed a login form was for people without the phone app.

Though for security, it doesn't preclude one from entering a password as a second factor, I suppose.

Re: SQRL - Replacement for usernames and passwords

#13
post #6

Not exactly a new idea. Here is some prior art http://openaccess.uoc.edu/webapps/o2/bitstream/10609/14761/6... http://www.computer.org/csdl/proceedings/ares/2009/3564/00/3... As far as I know, QR-TAN is being used in Germany for authentication by a number of banks.

Not only that, Google's OpenSesame did the exact same thing and worked for all Google users until they pulled it after it "went public".

So then they pulled it, told us something better was coming and nearly two years later, nothing.

Re: SQRL - Replacement for usernames and passwords

#14
post #5

How is this better than any other phone-based 2-factor auth scheme?

It's 1 step. Just scan a code. Con: requires internet connectivity, unlike some 2-factor implementations

Beyond that there's no explicit second-factor here, if you don't have Internet, what are you proving your identity to? If local, then run a local server...

Re: SQRL - Replacement for usernames and passwords

#15
post #5

How is this better than any other phone-based 2-factor auth scheme?

That's a question I have. One potential answer is that it moves authentication out-of-band, in case there's a keylogger or other malicious mechanism of the machine you're using. Also, it removes the need to remember a separate password for every site. Your master key is secured with a password, but that's it. It also removes the need to have a shared secret with a site, and doesn't require any third-party involvement.

He spends a good chunk of the latest episode of Security Now [1] describing it's advantages over current schemes. The episode isn't up yet (I listened to it on the the site's live stream), but it should be soon.

[1] http://twit.tv/sn

Re: SQRL - Replacement for usernames and passwords

#17
post #5

How is this better than any other phone-based 2-factor auth scheme?

It's not - it's really just a password manager. The "something I know and something I have" is completely removed by only requiring you to have the phone. If it's a password manager, then that is what it is; if it's meant for security, then it comes back to the recent article on fingerprints not being a password.

It's not really a password manager--there's no shared secrets. The site identifies you by a public key. For authentication, it gives you a nonce, and you sign it with the corresponding private key. All the secrets are kept on your device.

I've wondered about the "something I know" dimension as well. Perhaps a passphrase could be used (it already is used to secure the master key). It'd still be a major improvement, as only your local device would need it, and you wouldn't have to have a separate password for each site.

Re: SQRL - Replacement for usernames and passwords

#18
http://attrition.org/errata/charlatan/steve_gibson/

> Steve Gibson is somewhat of a "fringe" charlatan. In some professional security circles, he is not considered a reputable security professional, rather more of a snake oil salesman peddling third-rate software with bold claims. While many of his claims are a bit outlandish or bold, few, if any, are demonstrably false. However, when asked to speak on security topics, Gibson is getting adept at putting his foot in his mouth. A single amusing quote may be laughable, but a series of them begin to paint a picture of someone who doesn't really understand security. Rather, he seems to know enough buzzwords and ideas to be dangerous to his clients.

Re: SQRL - Replacement for usernames and passwords

#19
post #18

http://attrition.org/errata/charlatan/steve_gibson/ > Steve Gibson is somewhat of a "fringe" charlatan. In some professional security circles, he is not considered a reputable security professional, rather more of a snake oil salesman peddling third-rate software with bold claims. While many of his claims are a bit outlandish or bold, few, if any, are demonstrably false. However, when asked to speak on security topic…

Not to use a debate cliché, but isn't this a ridiculously shameless ad hominem? He's published the protocol and disavowed any intellectual property claim to it. Let's focus on critiquing the protocol.

Re: SQRL - Replacement for usernames and passwords

#20
post #6

Not exactly a new idea. Here is some prior art http://openaccess.uoc.edu/webapps/o2/bitstream/10609/14761/6... http://www.computer.org/csdl/proceedings/ares/2009/3564/00/3... As far as I know, QR-TAN is being used in Germany for authentication by a number of banks.

drivebyacct2 - your account has been dead for about 100 days and 200 posts, basically no one can seen your messages unless they have showdead on. Here's the "offending" post that you were banned for https://news.ycombinator.com/item?id=5982741 (hint - the ban is completely unjustified)
Post reply on HN