Thinking about Passwords
herman.bearblog.dev
herman.bearblog.dev
Git repo: https://github.com/62726164/ed25519-login
Test website: https://gen.go350.com/
I plan to write an Android and iOS app (someday) that has the same functionality as ed25519-login. We need to go password less, but the complexity of webauthn is too much IMO.
I'm looking for feedback and appreciate any suggestions.
https://aboutssl.org/ssl-tls-client-authentication-how-does-...
I do use TLS client certificates (with several APIs) but I don't consider them as password replacements (which is the goal of ed25519-login).
Disclaimer: I maintain an open source FIDO2 library.
However WebAuthn has the might of device-, OS and browser makers behind it which improves the chances of wide adoption and “what users will expect”-rate.
For those who do not want to understand all the complexity, but still leverage high security and “fingerprint / faceid” sign in on their web app we created passwordless.dev.
It’s a very easy way to try out and implement webauthn in your project. Happy to help fokes get started if you’re interested!
You can get your API key or run the demo on:
I used to use onetimesecret but find 1password to be sufficient to my needs.
[0] https://onetimesecret.com/ [1] https://blog.1password.com/psst-item-sharing/
Ignore below as I skimmed the article too quickly. Shouldn’t try and read something like this with screaming children in the room.
-
I think this proposal is a little more complicated than it needs to be, and it's adding a lot of friction to an already annoying login process. I run a site that has a registration option, people avoid it as much as possible.
Personally I'm a fan of the magic login email link, super simple and reliable. Just fingerprint/cookie the device that initiated the login to ensure that the email has been clicked on the same device.
Most services would be compromised my a users email becoming compromised due to "Forgotten Password" recovery systems. So a magic email login link is no less secure in my eyes.
I usually open these on my phone since it usually comes as a push notification.
You want to log in to x, there’s a place to put the owners email or phone number, they get (if you are previously on some “accept list”) a notification that let’s them grant or deny access. You don’t get to see any password, you just get logged in.
Ideally you’d also want them to be time limited and revocable.
Reminds me of SQRL for some reason: https://www.grc.com/sqrl/sqrl.htm
A somewhat similar solution to the same problems? Or at least follows the same kind of thinking to a different solution perhaps.
[1]: https://auth0.com/docs/authenticate/passwordless/authenticat...
Maybe you could elaborate on the problem statement? Passwords for what? And it seems presumed that these are services can't support token-based authorization; i.e. only support raw passwords?