Microsoft joins FIDO group to replace passwords with public key cryptography
arstechnica.com
arstechnica.com
http://twit.tv/show/security-now/435
He says the FIDO spec is overdesigned, and everyone there has their own interests, it's tied to certain technologies, and it's not free. SQRL on the other hand generates the keys on the fly instead of storing them on the phone for each website. If a hacker steals your identity, you can also get it back with SQRL - you can't with FIDO. He says SQRL is also much easier to implement.
https://www.grc.com/sqrl/sqrl.htm
http://www.sqrl.pl/ (fan-made)
Also, an interesting excerpt from Wikipedia, referring to when he announced the protocol for the first time:
> Within 2 days of the airing of this podcast, both the W3C and Google expressed interest in working on the standard.[2]
You really need common functional denominator in order this to fly.
Of course he was. He's Steve Gibson. He's a shameless self-promoter and he loves to make over-dramatic claims of finding security flaws in things.
His only saving grace is that SQRL actually looks pretty sound to my moderately-better-than-amateur security experience. I hate to admit it, because if it catches on as a standard, he's only going to become more insufferable. The guy is a kook, except he's a kook who maybe have actually done his homework this time. I'd still like to hear what some actual security researchers have to say about SQRL, because I'm sure as hell not going to take his word on it.
I admit "squirrel" does sound cool. But how is it different from any other challenge-response algorithm escapes me.
http://www.wired.com/wiredenterprise/2013/01/google-password...
How about this version from over a decade ago? Regardless of what you get to run inside it (we can substitute lots of stuff for the JVM used here), the form/style of it is simple and fits with habits that people already have.
The right is nice, too, in that it's harder to accidentally leave someplace, yet CAN be removed if absolutely needed. (unlike some biometrics, where "mugging you and taking your wallet/keys/pubkey-ring" can turn into "mugging you and taking your finger".