SnowShoe - Secure, intuitive, cost effective authentication for every device
beta.snowshoestamp.com
beta.snowshoestamp.com
I'm also thinking there's space out there for celestial navigation startup authentication system... so your 4sq / google lattitude / whatever claims you're in Alabama... prove it, point the phone at Antares click OK and Deneb and click OK and the azimuth / elevation celestial navigation related calcs had better match up for Alabama. I suppose "daytime people" could point the phone at the sun or something. Many ignorant people think the sun and moon are magically at perfect eternal opposition and it would be humorous to see how much funding you could raise based on that inaccurate assumption.
A Really interesting startup idea for a smartphone would be to use the victim... errr... the users social media location checkin to convince them to point the phone at a nearby landmark to obtain a az/el which theoretically an attacker would have a hard time figuring out ("Point the phone at the tallest skyscraper in sight and hold it there for 3 seconds")
If you're going to go for wild stuff for the sake of wildness, go gonzo, go all the way.
I completely agree.
* Authy
* Duo Security
* GetProve
* MePIN
* LaunchKey
* And now SnowShoe Stamp (it's a physical object you need for authentication)
All these have quite different goals, but strive to solve one problem - secure authentication. It will be interesting to watch how this develops.
PS. From all these I personally like Authy the most, but for my use case (many auths throughout the day from many users) it's too expensive. 20,000 API calls (for $99/mo plan) may seem a lot, but having only 500 users doing 4 auths per day will use it up already.
EDIT: Actually, the ideal solution would be to have an open source implementation of Authy, that you could deploy on your own web server, complete with corresponding iOS/Android Apps. One can dream...
Something like
http://www.norlin.se/blog/pam-module-for-sending-one-time-pa...
An alternative not exactly what you asked for, but does meet the "free and uses a (android) phone" criteria:
http://barada.sourceforge.net/
I've never messed around with PAM other than the usual kerberos / ldap / afs_session stuff, and some researching.
I did have the interesting idea that I could use one of the uncountable zillions of OTP implementations to generate a massive list of OTP tokens for a user (me). Then the server emails / sms or whatever precisely one OTP per hour. That solves the "I'll spend any time and money to avoid having to carry a paper printout of OTP keys". Although in a cost benefit analysis, for $100/month I think I could justify carrying around a piece of paper...
You could short circuit the OTP paper printout by simply (automatically?) shoving the whole list into your dropbox/evernote/email/whatever as a text file.
One obvious problem with sending a SMS every time user tries to log in, is if a swarm of 10000 zombie windows machines in China all decide to brute force your root (assuming you even allow direct root, or allow password auth as opposed to key auth) then even if you use some rate limiting to block each IP at 3 attempts, that still going to try to send 30000 SMS messages to the poor admin.
So its hardly unique in the world of security to say "be careful", but... "be careful".
This is useless as multi-factor authentication, because it turns it into single-factor authentication. Anyone sniffing a single session or seeing it once knows what it looks like, and can reuse it on any site. It's much, much weaker than TOTP/HOTP, for example.