3 ms·
There is another passwordless system called SQRL which is automated and more secure. From the user's perspective, they scan a QR code or click a browser extensi
by bendykstra 11y ago
There is another passwordless system called SQRL which is automated and more secure. From the user's perspective, they scan a QR code or click a browser extension and are signed into the site. Behind the scenes, a cryptographic challenge (a response URL + nonce) is presented to the user's phone or browser extension. The client signs the challenge using a per-site private key and sends the result to the provided URL.
https://www.grc.com/sqrl/sqrl.htm https://www.grc.com/sqrl/sqrl.htm
- Natanael_L 11y agoTiqr predates it and does the same thing. However, U2F and UAF from FIDO alliance are the new protocols that are being standardized, and they're looking good too. It is even designed to inherently resist tracking across services by using unique keypairs per service in a clever way. No device identifier is ever shared.
- ronancremin 11y agoAccording to Steve Gibson (SQRL's inventor) tiQr is quite different: "It superficially appears to offer a user experience similar to SQRL. However, as is every other such system, what's going on is actually far more complex and involves/requires establishing “shared secret” account credentials with the authenticating website. As they explain on their technical page, TiQr is based on the OATH (open authentication) OCRA protocol suite, which was standardized by RFC6287." https://www.grc.com/sqrl/other.htm https://www.grc.com/sqrl/other.htm