Beyond Identity Offers Free Version of Its Passwordless Technology
darkreading.com
darkreading.com
How to provide a good onboarding and UX around that process is another story. It requires educating the user to a different mindset.
I advise looking into Argent[1] (Loopring is the same) or BrightID[2] as just a few examples of how this can work well.
If you have no friends for social recovery, Argent provides their own service that links to your email or phone for recovery. So it’s more like a typical account recovery that users are accustomed to today.
Similarly, ZenGo[3] provides just that email/phone recovery service alone but it feels intuitive and safe depending on your threat vector. The cool thing about them is that it also uses facial recognition.
[2]: https://www.brightid.org/
[3]: https://zengo.com/
the actual blog post from Beyond Identity.
was really frustrated when the first link in the darkreading article just linked out to _another_ darkreading article. Like....wtf?
I like passwords + a YubiKey left permanently plugged into every device.
Of course that's a special case which doesn't apply to most people. But also, why can't the CGM just have its own display, which would simplify things a lot more and likely also require much less power if it used e.g. eInk?
It sounds ridiculous to me that a medical-grade device should depend on a second consumer-grade device to be useful. If it's an added feature for e.g. logging or monitoring or telemetry to the doctors, great, I understand, but if you're just trying to get a glucose reading I strongly believe in one device giving you that reading instead of "Hey I'm a device that your health insurance paid $1000 for but sorry I'm too lame to display data and you're going to need to install this silly iPhone app to actually read its values"
"and oh by the way we also will track your contacts, which apps you are using, your GPS, and serve you and your contacts targeted ads for glucose-free health foods from our partners at Amazon"
So I can check my blood sugar without taking my shirt off.
this is not two factor. that is two of the same factor.
the whole point of the factors is that they are fundamentally different, otherwise we'd just make people use two passwords and obscure feedback about which is wrong or right.
An authentication scheme is only ever as secure as its recovery process, so that's going to be where the magic happens.
I use a good password manager right now, but even so I find myself entering passwords many times per day. I'd love to not have to do that, so any tips on how I can do that are appreciated.
1. Service picks asymmetric scheme (RSA, ECDSA, etc.)
2. User generates public/private pair of keys locally
3. User registers its public key in the service
4. Now user can sign anything thus confirming its identity
No third-party service required. Users have to keep their private keys locally, but BeyondIdentity also requires this. I don't feel their complicated scheme has much sense. Also they've mentioned the use of machine learning, this looks even more strange.