Live data from Hacker News

SQRL - Replacement for usernames and passwords

grc.com

131–138 of 138 posts

Re: SQRL - Replacement for usernames and passwords

#131
post #79

Earlier quoted context omitted.

Using this type of technique (Clef and SQRL) on every login sounds like a particularly evil version of hell.

any particular reason why? I'd love to hear more of your thoughts...jesse @ our domain (if you have a second).

Getting out my cell phone, navigating to an app and then doing something or other with a QR code. For. Every. Single. Login.

And who knows what happens on a mobile site or app.

Yuck.

Re: SQRL - Replacement for usernames and passwords

#132
post #98
post #96

I think you can MITM this by presenting legitimate (proxied) ycombinator.com QR codes on e.g. ycombigator.com. The app would still authenticate to the legitimate site and then 'activate' the session, and ycombigator.com could have at it. HTTPS won't help either. The problem is there's no way for the phone app to transfer additional secure session cookies back to your desktop browser, so this has to be the case. Sure,…

This attack can be stopped by referer checking. A site that hosts a QR code should display a warning instead of the QR code if the referer doesn't match.

https does not expose referrer, and you are logging in through https, right?

Re: SQRL - Replacement for usernames and passwords

#133
post #131

Earlier quoted context omitted.

any particular reason why? I'd love to hear more of your thoughts...jesse @ our domain (if you have a second).

Getting out my cell phone, navigating to an app and then doing something or other with a QR code. For. Every. Single. Login. And who knows what happens on a mobile site or app. Yuck.

Fair enough; although, in our experience users have enjoyed the flow much more than passwords. I'd encourage you to give it a shot and let me know if it's as unbearable as it seems to you.

On mobile, when you click the button, you're just redirected to the app where you approve the authentication request and are automatically logged in.

Re: SQRL - Replacement for usernames and passwords

#134
post #18

http://attrition.org/errata/charlatan/steve_gibson/ > Steve Gibson is somewhat of a "fringe" charlatan. In some professional security circles, he is not considered a reputable security professional, rather more of a snake oil salesman peddling third-rate software with bold claims. While many of his claims are a bit outlandish or bold, few, if any, are demonstrably false. However, when asked to speak on security topic…

I can't make him out to be a buzzword slinger. I've listened to quite a bit of his show (although admittedly very little from the past year or so) and he definitely demonstrates good knowledge. Listening to him talk, my impression is that he brings the security mindset[1] to the table, rare among snake-oil peddlers or charlatans.

I think one of the main problems is that people in a field are generally critical of people who translate that field to a wide audience. You see that play itself out over and over. And that's what Steve does with his show, he tries to explain security to, more or less, laymen. And he only has an audio medium, which adds some difficulty. So, yes, he simplifies some things and this no doubt troubles a lot of security gurus.

Of course he's made mistakes on the show. I can recall a few, but most of them were caught and corrected later. He doesn't script it, so I'm sure you can find many examples of poor word choices or incorrect acronyms over the 300+ shows he's done.

I do think he's over-played the practical usefulness of some security products that he advertises on the show. I have experience with none of them (to my knowledge), but some of them just sound, to the trained ear, minimally useful. But, sadly, that's audio content advertising for you.

From the link, we have statements like:

> For whatever reason, Gibson tries to explain the Metasploit project as a "malware exploitation framework"

OK, that's a bad description. But he was describing Metasploit in passing using a description of Metasploit as it pertained to the subject at hand. And, if you read the actual transcript that they linked to, it was being used for malware exploitation. Seems like a silly nit-pick.

> You can't simply raise the spectre of global spying and hidden rootkits planted by Microsoft without either proving or disproving the allegation

No. If you see something alarming, you totally can. He didn't panic either.

> Steve said SSL connections are not susceptible to man-in-the-middle (MiTM) attacks? This is absolutely false.

Please. SSL/TLS has had vulnerabilities that allowed MITM attacks. They're ad-hoc and eventually get fixed. You can't just expect to MITM a random SSL connection. SSL is designed to be MITM-resistent, and saying "SSL prevents MITM attacks" is not in any way a bad description, especially when you're communicating to laymen.

> Further, having a switch does not absolutely prevent sniffing traffic. The popular Dsniff tool lets you do this.

Yep, he got that wrong.

> Close Steve, CSMA stands for Carrier Sense Multiple Access.

Yep, he got that acronym wrong. But I decided to check the next show[2]...

> [Steve] Also, I mangled an acronym, and I hate when I do that, especially acronyms that I know so well. I talked about CSMA, and I called it Collision Sense Multiple Access instead of Carrier Sense Multiple Access. And it has a CD on the end which stands for Collision Detection. [...] So the real acronym for Ethernet is CSMA/CD, which is Carrier Sense Multiple Access with Collision Detection

So he switched a word in an acronym, then corrected it next episode. But they complained anyway. I couldn't have scripted it any better to what I said above.

Those examples were skimmed from the first three links. The authors came across like they had a vendetta to nit-pick everything they could. They've blown their own credibility already as far as needless nit-picking, missing the forest for the trees, and not checking to see when he corrects his own mistakes (aka, doing their homework).

I'd hardly summarize all that as a "fringe charlatan". He may be a bit fringe-ish, but I don't see how he's a charlatan.

[1] https://www.schneier.com/blog/archives/2008/03/the_security_...

[2] https://www.grc.com/sn/sn-017.txt

Re: SQRL - Replacement for usernames and passwords

#135
post #125

Earlier quoted context omitted.

There is no such thing that could never happen again under that thought process. Google Boltzmann brain to see what I mean. If never is to have any meaning at all, it is in situations like this.

There is one thing that could never happen. Something that's mathematically perfect fits that criteria - the One Time Pad. Even at actual infinite available time frames i.e. you travelling at the speed of light, with quantum computer on board your ship powered by the unobtainium drive, even with that sort of time frame, you shall never be able to decrypt the correct message.

> Something that's mathematically perfect fits that criteria.

No, it doesn't. A one-time pad still needs a source of randomness, and a guarantee no reuse. How certain are you that you don't have a backdoored RNG, or initialization vector reuse?

Or, for a fully general argument, how certain are you that we're not living in a computer simulation, where the Dark Lords of the Matrix can just lookup their logs to see what random values were generated for your one-time pad? Or if we go to that extreme, how can you be absolutely certain of the truth of anything - including mathematics - if said Dark Lords could be messing with our brain and memories?

Or more mundanely, how about this: a flurry of cosmic rays strike the RAM containing the message and by random chance flip the same bits that were set in the on-time pad. Tada, message decrypted.

I'm pretty damn certain none of those hypotheticals are the are even remotely worth worrying about. I may even be more than P(1 - 2^-512) certain that they are false. But it's still merely a very high, finite probability. P(0) or P(1) don't exist - you can approach them, but you can't ever reach them.

Any idea, no matter how crazy or out of place with our understanding of the universe could happen, at least in principle. Therefore if we want “never” have a meaning at all, we need to set an cutoff point where we stop caring. Obviously an appropriate value depends on the situation, but in this case I'm pretty sure that an appropriate cutoff is somewhere up of P(2^-512).

Re: SQRL - Replacement for usernames and passwords

#136

Earlier quoted context omitted.

Right now, sites need to explicitly integrate with us. We've thought a lot about creating something that manages passwords to bridge the gap. We've actually been working on this with some community members (Joe is here somewhere) and are hoping to roll something out in the next few weeks. Sorry for not addressing the footnotes! 1. exactly, we generate a digital signature similar to SQRL 2. right. from a technical per…

Thanks for the answers. I'll be looking forward to see it hit hackernews.† :) I've mentioned it elsewhere here, but i'd suggest you also look into https://github.com/habnabit/passacre , since its creators put a LOT of value in getting the crypto parts right and its main creator is very responsive online. And thanks for answering the footnotes. It is an interesting thought that users can be helped by the wiggling anim…

Mithaldu, just as a reference, I'm the guy working with Clef on enabling Clef on more sites.. We've got a pretty cool system, and it's getting dang close to release. Hopefully I'll have it finished soon!

Re: SQRL - Replacement for usernames and passwords

#137
post #117
post #98

Earlier quoted context omitted.

This attack can be stopped by referer checking. A site that hosts a QR code should display a warning instead of the QR code if the referer doesn't match.

The malicious site in the middle can download the legit QR server side (e.g. using PHP) and simply spoof the referer, then present it to the visitor. Where will a referer check help?

That's a great point. I didn't think of that.

Re: SQRL - Replacement for usernames and passwords

#138
post #125

Earlier quoted context omitted.

There is no such thing that could never happen again under that thought process. Google Boltzmann brain to see what I mean. If never is to have any meaning at all, it is in situations like this.

There is one thing that could never happen. Something that's mathematically perfect fits that criteria - the One Time Pad. Even at actual infinite available time frames i.e. you travelling at the speed of light, with quantum computer on board your ship powered by the unobtainium drive, even with that sort of time frame, you shall never be able to decrypt the correct message.

Also, see this:

http://www.gwern.net/The%20Existential%20Risk%20of%20Mathema...

Post reply on HN