Live data from Hacker News

SQRL - Replacement for usernames and passwords

grc.com

71–80 of 138 posts

Re: SQRL - Replacement for usernames and passwords

#71

Earlier quoted context omitted.

As a counterpoint: It's far more likely i might be mugged for the easy cash scored by a phone that has a 500€ market price, than to have my desktop stolen. ;) One more question: How about sites which don't have clef implemented? Can i enter a URL into the clef app (or use some kind of JS scriptlet to generate a QR code on the fly) and have it generate me the password for that, so i can type it in manually? Maybe even…

Right now, sites need to explicitly integrate with us. We've thought a lot about creating something that manages passwords to bridge the gap. We've actually been working on this with some community members (Joe is here somewhere) and are hoping to roll something out in the next few weeks. Sorry for not addressing the footnotes! 1. exactly, we generate a digital signature similar to SQRL 2. right. from a technical per…

Thanks for the answers. I'll be looking forward to see it hit hackernews.† :)

I've mentioned it elsewhere here, but i'd suggest you also look into https://github.com/habnabit/passacre , since its creators put a LOT of value in getting the crypto parts right and its main creator is very responsive online.

And thanks for answering the footnotes. It is an interesting thought that users can be helped by the wiggling animation of the barcode and its inherent suggestion. (That would be worth a trip report on how you got there.)

† I'd prefer to follow an rss feed, but your blog seems to be 90% marketing and only 10% user-relevant posts with no categories.

Re: SQRL - Replacement for usernames and passwords

#72
Here's why this is stupid: This is 1-factor authentication, but it's actually LESS secure than a username and password.

A password is something you know - it's in your head, so it can only be stolen if you save it somewhere, or if there's malware on your computer sniffing it.

The tokens in the phone are saved in the phone, so if you lose the phone, you've just lost your password/set of keys. On top of that, malware in the phone can extract the keys.

With malware on your phone, your accounts can be pilfered without your knowledge, at any time. Or if your phone is stolen. This is different from 2-factor, where you have to both know a secret AND have access to a device.

(If the prospect of malware on your phone doesn't phase you, consider that news articles over three years old reported hundreds of thousands of malware installs found by various security companies)

Re: SQRL - Replacement for usernames and passwords

#73

Here's why this is stupid: This is 1-factor authentication, but it's actually LESS secure than a username and password. A password is something you know - it's in your head, so it can only be stolen if you save it somewhere, or if there's malware on your computer sniffing it. The tokens in the phone are saved in the phone, so if you lose the phone, you've just lost your password/set of keys. On top of that, malware i…

The key on the phone is of course encrypted with a password.

Re: SQRL - Replacement for usernames and passwords

#74

Here's why this is stupid: This is 1-factor authentication, but it's actually LESS secure than a username and password. A password is something you know - it's in your head, so it can only be stolen if you save it somewhere, or if there's malware on your computer sniffing it. The tokens in the phone are saved in the phone, so if you lose the phone, you've just lost your password/set of keys. On top of that, malware i…

Malware on the phone isn't covered by their attacks and weaknesses page. (https://www.grc.com/sqrl/attacks.htm)

The Userview page seems to miss that point as well: (https://www.grc.com/sqrl/userview.htm)

> In other words, only the smartphone's owner can use the system to assert their identity, and nothing will prevent them from asserting their identity whenever they wish to.

I think they mean "only the person currently in possession of the smartphone" ...

except they go on to say that whoever has the phone has to identify themselves to the phone using a strong password.

> The SQRL system was specifically designed to eliminate username and password authentication to remote websites. But controlling access to SQRL authentication itself requires the smartphone's owner to prove their identity to their own phone.

> And to that end, “a secret only the user knows” is still the best technique for users to repeatedly, quickly, easily and privately prove their identity to their own smartphone.

> The cryptographic design of the SQRL system inherently provides identification security for every website it contacts. In that sense the system itself is fully secure without any password protection. We refer to the SQRL password as a “local password” because it is only used to prevent others from using the SQRL smartphone app to impersonate its owner.

Re: SQRL - Replacement for usernames and passwords

#75

Earlier quoted context omitted.

Right now, sites need to explicitly integrate with us. We've thought a lot about creating something that manages passwords to bridge the gap. We've actually been working on this with some community members (Joe is here somewhere) and are hoping to roll something out in the next few weeks. Sorry for not addressing the footnotes! 1. exactly, we generate a digital signature similar to SQRL 2. right. from a technical per…

Thanks for the answers. I'll be looking forward to see it hit hackernews.† :) I've mentioned it elsewhere here, but i'd suggest you also look into https://github.com/habnabit/passacre , since its creators put a LOT of value in getting the crypto parts right and its main creator is very responsive online. And thanks for answering the footnotes. It is an interesting thought that users can be helped by the wiggling anim…

We're working on the blog :D

I'll definitely make sure to look over passacre; it seems great.

And no problem on the footnotes, if you ever have any more questions don't hesitate to email me at jesse at our domain name!

Re: SQRL - Replacement for usernames and passwords

#76
They don't offer a reference implementation.

The documentation provided is a bit rambling and jumps around; it has stuff people don't need and doesn't have some stuff people do need.

It's a bit scary to think that people are going to implement some crypto stuff based on just this and release it into the wild as a secure solution.

There's a similar problem with password safes - some of them seem secure enough, but there are many and who knows whether those are any good or not.

Re: SQRL - Replacement for usernames and passwords

#77

Here's why this is stupid: This is 1-factor authentication, but it's actually LESS secure than a username and password. A password is something you know - it's in your head, so it can only be stolen if you save it somewhere, or if there's malware on your computer sniffing it. The tokens in the phone are saved in the phone, so if you lose the phone, you've just lost your password/set of keys. On top of that, malware i…

Mobile malware is overrated. People have been making a lot of noise for a long time, there's hardly any actual infections observed in the real world. http://chazlever.com/publications/traffic-ndss13.pdf

Re: SQRL - Replacement for usernames and passwords

#78
post #36
post #20

Earlier quoted context omitted.

drivebyacct2 - your account has been dead for about 100 days and 200 posts, basically no one can seen your messages unless they have showdead on. Here's the "offending" post that you were banned for https://news.ycombinator.com/item?id=5982741 (hint - the ban is completely unjustified)

Ahem. ( https://news.ycombinator.com/item?id=5974604 )

Dan is right. I assumed that was why I was hellbanned and I was clearly behaving poorly in that thread. Fortunately, since they brilliantly combined a hellban with a slowban, I knew immediately. I'm not really sure why I keep posting - figured I goofed [that thread is embarrassing] and I'd feel dumb groveling to have an account unbanned when people create one-off troll accounts everyday here.

Though it is frustrating when I see entire threads go on about bits of technology and then my comment is the only one pointing out some super relevant related tech. Oh well.

Re: SQRL - Replacement for usernames and passwords

#79
post #57

This looks like a much less polished version of Clef ( https://getclef.com/ ). Clef is a really awesome app and they're already powering this type of integration for a few hundred websites. One of the founders is an HN regular, although I can't remember his username (Jesse, reply if you see this).

Using this type of technique (Clef and SQRL) on every login sounds like a particularly evil version of hell.

Re: SQRL - Replacement for usernames and passwords

#80

Here's why this is stupid: This is 1-factor authentication, but it's actually LESS secure than a username and password. A password is something you know - it's in your head, so it can only be stolen if you save it somewhere, or if there's malware on your computer sniffing it. The tokens in the phone are saved in the phone, so if you lose the phone, you've just lost your password/set of keys. On top of that, malware i…

No, it's two factor.

If you look at the crypto page the scheme he proposes uses an 'identity password' in combination with a strong KDF (scrypt). The resulting hash is XOR'd against the masked master device key.

Post reply on HN