Show HN: Logging in with QR codes (proof of concept)
blog.self.li
blog.self.li
So basically you want one-time session tokens. This is only slightly secure if you do the "first" login on the phone, not on the desktop, since you don't trust the desktop. You can achieve one-time session tokens with an app on your phone that doesn't need network access, such as a one-time pad or some kind of HMAC token-generating app (display a token, user enters into app along with their secret key, a new token is generated, put into desktop login and poof, you have a secure one-time token). You can do that with QR codes to prevent from having to type stuff.
As a more elaborate version, this could provide a challenge-response authentication where the QR code is the challenge, an Android/iPhone app does a crypto hash to sign the challenge and sends it to the home office to complete the authentication.
Unfortunately, webcams are not consistent WRT presence and access, otherwise the phone app could generate a signed QR code and send it back to the home office via the webcam. The primary advantage here would be if you did not have internet access via your cell phone, e.g. neither cell phone coverage nor a WiFi hotspot was available.
http://animate-innovations.com/content/animate-login
We're very open to getting help & feedback!
peace,
isaac <ijones@syntaxpolice.org>See http://www.youtube.com/watch?v=te_sgFo5wdo for more info.
https://nomopass.com/ is the developers' attempt at a SaaS solution.
One is called Snap2Pass: http://prpl.stanford.edu/papers/soups10j.pdf http://www.youtube.com/watch?v=-9QOcDV4VZI
Here's one called Animate Login with source code: http://animate-innovations.com/content/animate-login
edit: nevermind, this is a different, more like finger print scanners than my idea. That teaches me to skim articles at first. Still a neat idea!
Do you have QR-enabled cameras at each door? Is it a custom solution?
Here's a brief post I did on the lock system itself: http://adrianpike.tumblr.com/post/6009384439/door-locks-on-r...
Source is over on GH, but it would be pretty straightforward to roll your own nice & quick. If you do want to use mine, I'd be totally willing to help hack in new features, I've got lots of stuff I want to improve it with, but just don't have the side project time.
I'd prefer to scan a QR code on a page then enter a capatcha. I think for things even simpler then logging in, QR codes could be a reasonable alternative to difficult web forms, id verification, etc.
It is at http://www.kirubakaran.com/passtrust/ It has email confirmation on creation of the account (first log in) but I've temporarily disabled it as I am making some changes.
The standard is definite for how to create QR codes, but I don't like how there are no written standards for how to pack the data (e.g. contacts, events, messages)
That all being said, and as interesting as it is, I'd be more interested in something that could use, say, push notifications (and Android intents specifically, unless there's an iPhone equivalent) as a smooth implementation of some sort of public key authentication.
Push notification would work as well as SMS, but you have to install app for that.
qr codes are cool so you don't have to type adresses when you see a poster, billboard, etc. or a mobile link on a website
Huh?