3 ms·
>intercepting traffic or spoofing a site can copy/tamper/replace the QR code Will this be a problem with HTTPS? When you open a page, a request will be made t
by PranavBerry 5y ago
>intercepting traffic or spoofing a site can copy/tamper/replace the QR code
Will this be a problem with HTTPS?
When you open a page, a request will be made to my server to generate a unique login attempt, the id of this unique login attempt will be shown in the QR code.
When you scan it and enter your phone's pin, my authenticator generates a signature of the login attempt id, your username on that website and the current time. My server verifies the signature and logs you in if everything is ok.
Have you logged in to the Discord/Reddit/Whatsapp websites by scanning the QR code shown there from their mobile app? My concept is the same but using my authenticator app, websites which do not have a native app can also offer a QR code login.
- LinuxBender 5y agoI've seen people use QR with those sites and it doesn't make sense to me. So using a bank as example, I barely trust them to get this right. Now I am inserting your company into the chain of trust? Why am I trusting one more party to get all of this right? Or is this a solution you are selling to each vendor and they are implementing your service on prem? Is your service going to be audited by independent third parties that vendors choose? How do people verify that your application is the legitimate version? How does the bank know if someone has tampered with your application? Why is my bank trusting your application?
- PranavBerry 5y ago>Is your service going to be audited by independent third parties that vendors choose? Yes I am planning to do that. >How do people verify that your application is the legitimate version? How does the bank know if someone has tampered with your application? I will use SafetyNet to check that the device is not rooted/jailbroken and that the signature is being made from my app.