Django-qrauth: QR codes for instantly signing in to a website
github.com
github.com
My idea for auth with QR codes would work something like:
a) initial setup: user establishes profile with website, including creating a public/private key pair. Public key stays with the service, private key in the user's phone/app.
b) To authenticate, website presents user with QR code containing a token encrypted with user's public key.
c) user scans code with phone/app, decrypts token with private key, signs it, and returns it to service, which verifies token and signature thus authenticating user.
But then all you've done is validated the user on his/her phone... not on the computer displaying the web page with the original QR code. What am I missing?
0. The user must be already logged in to the website on their desktop via any conventional means.
1. The website generates a QR code with a hard-to-guess URL, unique for the user.
2. The user reads the QR code with their phone, and opens the link in the mobile phone's browser.
3. The URL is unique for the user and hard to guess, so the user can be logged in their mobile browser without asking for an username and password.
1. If there are XSS vulnerabilities on the website, an attacker could be able to use iframes (at least if you haven’t set X-Frame-Options to DENY) or XMLHttpRequest to retrieve an authentication QR code and use it to log into the user’s account.
2. Even without any XSS, it is possible that someone who has access to the user’s session (for example, if the user is still logged in on the website, but is away from the computer) could scan the QR code and, therefore, log into the user’s account.
Possible solutions include sending the QR code by email (actually, some users are always logged into their email accounts as well, so this might be meaningless) and prompting the user for their password before displaying the QR code (it is still much easier to type the password on a desktop/laptop computer’s keyboard rather than type the site address + login or email + password on a mobile device’s virtual keyboard).
[[UIApplication sharedApplication] openURL:targetURL];
where targetURL is an NSUrl.
Chrome on iOS even allows you to specify a callback URL to return to.
[1] https://developers.google.com/chrome/mobile/docs/ios-links
Hands-down, the most mature option for iOS.
I'm not sure if it's the exact same process though.
Following the advice of Linus Torvalds [1] and other wise, experienced technical leaders, I suggest all working engineers avoid idly reviewing patents or patent claims unless and until a patent expert representing your own interests advises that there is a credible threat of legal action and need to understand specific patents.
Otherwise you're helping trolls and wasting time getting worked up over what is, 99.99% of the time, nothing.
It's currently in the App Store review queue but I would be happy to provide a private build for those interested.
Works on any site, no plugins or backend/server modificatons required.
If you're still interested, mail me at info@seqrentry.net and I'll make sure you get a copy as soon as it's in a workable state.
But QR codes are probably a bad way of going about it. The average user just doesn't know what to do with QR codes, and they have poor engagement (at least if you're targeting this at non-Asian countries). How often have you ever seen someone scanning a QR code? They're particularly a waste of space on advertising--where that space could be used to place a URL that people know what to do with.
Perhaps a better way to go about enabling this login process is asking for their mobile number, and then just SMSing them a link to click.
A few more reasons:
1. There are always third parties (the SMS gateway, the carrier) when you send SMS messages.
2. You cannot receive SMS if there’s no signal or if there’s no cellular module at all (a frequent use case on tablets, iPods, etc) — just the camera, Internet connection, QR code scanning application. :)
3. Sending SMS messages costs you money. In another hand, QR codes are generated for free. Also, it usually takes more effort to set up (and also it can break — relying on third party services is almost always less solid).
4. SMS messages can be slow (and sometimes you don’t receive a message at all). QR codes, in another hand, are very predictable and usually work pretty well (at least if the camera works correctly).