4 ms·
No more username, passwords and your are in control. Seems like a perfect protocol for login and authentication. How will it work on mobile only world? Can thi
by jelv 9y ago
No more username, passwords and your are in control. Seems like a perfect protocol for login and authentication.
How will it work on mobile only world? Can this also work on iOS and Chrome OS?
- cm2187 9y agoYou would typically store the private key on a single device to reduce the risk of leaking it. Authentication on another device is done through the QR code. Authentication on the same device is done through the SQRL app registering a protocol. So you tap on the QR code, it opens a SQRL:// url which opens in the SQRL app, the app authenticates, the websites redirects you to the desired authenticated page.
- jelv 9y agoSo my ID's are in my SQRL app on my laptop or phone. Can I sync my ID's between my laptop and phone? I don't want to be forced to use my phone to scan a QR code on screen for every site.. Can 1Password implement SQRL?
- cm2187 9y agoI don't know about the particulars of the app, but at the end of the day, the only data stored in the SQRL app is the private key. All website specific keys are derived from a combination of the domain of that website and of the private key. So there is no need for a sync mechanism per se, outside of originally sharing the private key. That being said storing that key on your (encrypted) mobile only is what protects you. There is an option to maintain the state of which websites were used to authenticate, but that's only to reset your access should your private key be compromised (or mobile stolen). Then your SQRL app should sync the list of websites with some central location. This would ensure that the day you think the key is compromised, you can reset all access to all websites with a new private key automatically (this is part of the SQRL protocol). On 1Password, I don't see why not. Gibson made the protocol open source and free.