2 ms·
The four PDFs present on the SQRL page to a better job explaining than I will here, however I'll summarize a bit: The SQRL client registers the sqrl:// prefix
by JamesonNetworks 6y ago
The four PDFs present on the SQRL page to a better job explaining than I will here, however I'll summarize a bit:
The SQRL client registers the sqrl:// prefix to pass the login challenge to the SQRL client. The client, after a password or the pin (depending on if the password is present in RAM) is entered, responds to the server using signed credentials which are only valid for the domain being authenticated. That challenge creates a logged in session for the user and redirects back to the website.
There is also a QR code method of logging in, which depends on the user to confirm the domain name of the site being logged into. This is admittedly less secure, however, does provide some handy convenience when on an untrusted system by not requiring a user to give up their password. There are attacks that can be used to gain a session, however, these are thwarted when the on device authentication path is used (which requires some software to be installed on the users device)