34 karma · joined April 9, 2013
We received a number of requests from (ex-)Clef users asking if we would perhaps build an authentication plug-in for WordPress, now that Clef is sunsetting.
This is our first version: We opted to use a proven extension as a base, and collect feedback. Then use that to develop a stand-alone plug-in in the future.
Tell us what you think!
- Pieter
A third, replacing our current auth flow with SecureLogin indeed isn't likely to work for reasons you mention.
I applaud this initiative since it lists exactly the reasons why we started Authentiq: Decentralization, usability, privacy, safety for end users (which is very different from merely offering security features that most people don't use).
Authentiq is similar in goals and architecture, yet with a more comprehensive feature set, since we aim to support existing standards (like OIDC) as the integration point for developers, and offer a more complete mobile identity to end users so that the site owner doesn't need to store those details either.
That said, I'm very keen to see if we can add support for the OP's authentication protocol soon. Check us out here if interested: https://www.authentiq.com/
Key loggers anyone?
With Hetzner that is indeed a necessity. They sell cheap iron, but don't expect any support from them and be prepared to move out quickly.
I really like the UX of SDC; are Disconnect or DoNotTrackMe just clutter, or adding value still?
Two notes:
2) No need to mask requests with a HEAD; a GET can also return a 304 directly.
6) De-duplication of calls: Any method except POST should be idempotent already, hence also a retry-on-error is trivial in those cases.
No risks for an LTS release I guess.
security.tls.version.max = 3
security.tls.version.min = 1
security.ssl3.rsa_fips_des_ede3_sha = false
in about:config, after which it also said "Probably good" for FF26.That's a very bold and yet to be proven statement. Probably any crypto expert would know better than to say that.
This paragraph exactly pin points the problem with being a cryptographic nobody.
PS. I do like their icon designer.
https://class.coursera.org/crypto-008/class
The Russians made the same mistake in WWII, but Whatsapp shows the relevance today.