(Someone plz fork Chromium and build this in! And hit me up when you want me to make the Django/ExpressJS auth plugin for it.)
(Someone plz fork Chromium and build this in! And hit me up when you want me to make the Django/ExpressJS auth plugin for it.)
Soon you'll be able to use TouchID to log in to your website, provided you've associated the pubkey from your fingerprint authn with your website.
https://www.chromestatus.com/features#component%3A%20Blink%3... (TouchID on MacOS: TBD)
https://bugs.chromium.org/p/chromium/issues/detail?id=780078... (CTAP2: merged)
https://www.chromestatus.com/features/6288375388569600.
We're integrating webauthn for our medical clinics as a way to support easy, secure authentication without 2FA to reduce sharing of ipads with a session logged in.
More reading: https://duo.com/blog/developments-to-webauthn-and-the-fido2-...
In fact, unlike a house key, the Security Key works fine for its new owner, they can register it to sign into their Facebook, or whatever, that will work fine. Facebook will have no idea it's your key, now it's their key.
If they know you're simongr3dal@example.com on Facebook then that's a problem, yes, as obviously they can sign in as you, but if it's so hard for you to remember what you signed up to, seems like it'll be pretty hard for a hypothetical finder to figure out too... "Hmm, I wonder if this random stranger was into Diaper Porn and Antique furniture?"
The upside would be that you could tie a cert to a specific hardware device and serial number, which means someone getting your certs won't be useful to them. Microsoft does something like this for xbox "machine" accounts. Each device can have it's own password that is tied to that serial number. If leaked, the password (or cert in this case) is not useful anywhere else. This is similar in concept to tieing an ssh public key to a specific network or IP address, except it is a hardware identifier in this case.
Unpopular opinion disclaimer: Anything else pretty much requires tieing into some 3rd party auth service or hardware token which have their own issues, such as vendor lock-in, managing server side libraries, leaking usage data to 3rd party providers, creating weak-chain back-doors to 3rd party vendors, privacy violations, etc.. I know those are all the rage right now among technical folk, but the general public adoption is quite low. Passwords will be around for a very long time.
For most other things Kerberos (via PKINIT) is used.
SSH authentication X.509 using PKIXSSH is rarely used since it is not a standard part of any operating systems used. For SSH, typically either Kerberos or SSH keys based on the RSA keys used by the certificates.
Built into browser would be more user friendly, admittedly, but in my opinion this is quite good too, and arguably more secure as your private key is not exposed to your PC.
Also see: https://w3c-ccg.github.io/did-spec/
https://blog.codesolvent.com/2015/07/why-not-signed-password...