4 ms·
There's a larger reason for not using this and using a community standard (SAML2 is all over the academic community, with a few million active users, tried and
by iheartmemcache 10y ago
There's a larger reason for not using this and using a community standard (SAML2 is all over the academic community, with a few million active users, tried and true -- JSON Web Tokens/WS-Fed/etc all work too) - standardization and interoperability. Authy/OneLogin/Anyone-who-supports-SAML2/WS-Federation is doing the Right Thing(tm) [1] by supporting standards and breaking out of the walled garden. It's time to stop leaving our authentication to corporations. I would have sounded like a tinfoil hatter, but Snowden et al have vindicated me so I'll continue to vocally extol alternative methods and the re-decentralization of the internet. Crypto's our last defense against malice and incompetence.
That RSA handshake saying "hey, it's me-- check the Web of Trust & the fingerprint of this public key I gave to you in person")/identity verification(there's a reason why you not only encrypt but sign your data with PGP) is especially now important to run on your own server & effectively trivialto set up with Docker (which I'd bet at least 70 percent of the readers here use.) To add SSO support for SAML2 (or JWT, or whatever you want-- passport.js supports it all) so others can use their own IdP's to authenticate in via WS-Federation is now trivial.
One day there's going to be some catastrophic data leak of the magnitude of the Philippines leak, of the social importance of the Panama Papers, and of the shock value of the Ashley Madison leak and we'll only have ourselves to blame for making our fun toy web-apps auth against only FB and Google.
[1] This has been a "solved" (mathematically + progmatically via PGP 2.0 for ~25 years with Zimmerman's implementation of the Web of Trust). Who remembers key-signing parties?! Haha. If you lose your key, you call up your buddy Bob who has an authentication claim with the sole ability to talk to the Identification Provider, Alice (whom you and Bob both trust to run your SSO) and your certificate is immediately revoked, so even if your private key and passphrase and device are all lost, no new data the second your key's state moves to 'compromised'. Alice can pull the plug on her RasPi's IdP, killing the whole and I might sound like a tin-foil hatter but re-decentralization for the internet has never been more important. She can pull the plug on it or have a cron-dead-mans-switch that discharges ESD to the volatile RAMdisk and kills the power, at worst she'll get an obstruction of justice charge. Multi-national corporations will comply court-orders if their in-house counsel says the demand isn't viably disputable.
The internet was rooted in academic/sharing culture, and ARPAnet was designed with decentralization as such a fundamental component that redundancies were put in place to literally route information successfully with a significant part of the nation offline as a result of nuclear war. Walled gardens like this are inherently vulnerable to government intervention. That Israeli firm compromised (as I understand it) the iPhone in the 'pwned' sense. If this is a reaction to the public distrust of iPhone as a platform, this isn't any more secure than before. Apple still has to have the initialization vector/nonce/whatever that's seeding the pseudo-random number generator.
From the BSD[2] culture we came, to there we must return.
--
[2] More so referring to the culture of EDA semi-conductor tooling & the attitude of "here, take it, use it, and enhance it, and release it back into public domain, more so than the whole BSD 'the SysV UNIX competitor' and all of the derivatives were spawned from it).
See: https://en.wikipedia.org/wiki/VLSI_Project https://en.wikipedia.org/wiki/VLSI_Project, https://www.mosis.com/products/fab-processes https://www.mosis.com/products/fab-processes (which yielded SPARC), http://wiki.geda-project.org/ http://wiki.geda-project.org/, etc. IBM was also was the other instrumental player in the 70s/80s to enable chip-houses to get past that proverbial wall of a few hundred k components on an IC. Rumors around the EE scene has it that low-run-custom-SoC's are the next B2B move chip houses are going to push, but we'd still be on System/36s and VAXstations if if it weren't for some associate professor in his 30s and a few 25 year old PhD candidates who pushed out the chiptooling that's still in use today (MAGIC, SPICE, and all the subsequent derivatives).
- robin_reala 10y ago(Add to that several million the million+ GOV.UK Verify users of SAML2)
- Rafert 10y agoAnd the 12 million Dutch citizens using DigiD.
- Freak_NL 10y agoNot exactly a shining example of proper authentication. I don't particularly like being forced to use a mobile phone for government authentication (because of the text message token requirement). It would be nice if we could get some decent two-factor authentication in the next iteration. I hope Idensys (DigiD's successor) will get the hardware factor right, and provide a truly cross-platform solution that does not involve mobile phone numbers.
- Natanael_L 10y agoU2F / UAF seems good enough for authentication.
- scrollaway 10y agoYou'll probably be interested in Let's Auth, a WIP spiritual successor to Persona meant to take 3rd party auth back from the grips of twitter/facebook exactly for the reasons you mention. https://github.com/letsauth/letsauth.github.io https://github.com/letsauth/letsauth.github.io