3 ms·
FWIW, this is something U2F somewhat solves. There is still the following exhaustive list of problems: 1. Education for and purchase of U2F keys 2. Key loss re
by STRML 8y ago
FWIW, this is something U2F somewhat solves. There is still the following exhaustive list of problems:
1. Education for and purchase of U2F keys
2. Key loss recovery mechanism
3. Key stolen defense (you can't just rely on the U2F key alone, there must be a pw or other type of second factor)
4. Widespread browser & device support (without it, a user/pass is required as a backstop)
Nevertheless, it is progress.
- z3t4 8y agoA problem with U2F and prior solutions is that they are hard to implement and public/private key pairs are specific to website origin, meaning I can not use the public key as an identifier. We need something much more simple, basically all it needs to do is to proof the possession of the private key. It would however have the same problems, those you mentioned, which are difficult problems. My idea in order to make those problems less painful is to require key rotation at regular intervals, that way people will automate away those pain points. For example by generating two backups keys that the user is instructed to store off-line, which is then used every second month to rate keys, and can be used as proof of you owning a lost key. Then you can implement certificates etc independently eg proof that the person holding the key is a certain person. But it's important that such things are not in the spec - or it would be too complicated, leading to no- or slow adaption.