4 ms·
In practice, FIDO U2F (Universal 2nd Factor) provides the same benefits and side-steps the major pains associated with mutually authenticated TLS (convoluted us
by phlo 8y ago
In practice, FIDO U2F (Universal 2nd Factor) provides the same benefits and side-steps the major pains associated with mutually authenticated TLS (convoluted user experience, complex trust relationship management).
Google reportedly managed to all but eliminate phishing targeted at employees [1].
They also kind of solve your point 2: since the credentials live on the token, it's easy to move them from one device to the next. For devices with USB/NFC, that is.
[1] https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/ https://krebsonsecurity.com/2018/07/google-security-keys-neu...
- erpellan 8y agoPoor UI around client-side certs isn't a law of nature, it's not a priority for browser vendors. It should be super simple. Once you're signed up, the exact same tech that lets a browser show you the green padlock with the name of the site could seamlessly log you in with zero interaction needed, IF client side certs were easier to use (which is within the compass of the browser companies to improve).
- Osiris 8y agoPortability. You need to have access to your authentication mechanism from multiple devices, phones, laptops, desktops, even other people's computers. That's why the password still exists. I raised this issue with the WebAuthentication standard on their GitHub and the first reaction was to doesn't its importance. I log into services from a least the different devices every day.
- tialaramex 8y agoSo, the correct way to approach this in WebAuthn, which you'll see in popular implementations of its predecessor U2F and in for-real WebAuthn deployments is that users are allowed to have any plausible number of tokens, in GitHub this feels especially natural because it's managed the same way as your SSH keys, you can add or remove them, give them labels that help you remember what they are, and then you use any of them to prove your identity. So I have a cheap FIDO token on my keychain that I take everywhere, and then I have one permanently plugged into the big desktop PC in my home and one in a desk drawer. You can buy ones that work nicely with a phone (unless you have an iPhone, can't help Apple) and Microsoft intends to effectively build one into Windows installs. If you see a WebAuthn deployment that does 1:1 users to FIDO tokens, those people don't know what they're doing and need re-educating just like when people go "Oh, MD5(password) seems pretty secure".