3 ms·
> Logging into a website: rather than typing your password into a potentially unsafe website, you can simply send a proof that you “know your password”. Authen
by vikas-kumar 5y ago
> Logging into a website: rather than typing your password into a potentially unsafe website, you can simply send a proof that you “know your password”.
Authenticating your identity: rather than giving your mother’s maiden name over the phone to a random, bank call center agent, you can simply send a proof (a cryptographic fingerprint), that you are who you say you are.
These examples tipped me off. Can someone help me understand how it is safe. Say one can send the exact cryptographic fingerprint and impersonate me. How is this anything better than me just sending password to authenticate?
- baby 5y agoThink built-in authenticators like touch ID or face ID. What they do is that they authenticate you via biometrics, and then unlock a private key stored on your device that will sign a challenge. The challenge is only relevant for some situation, so that you can't replay it. Essentially, signing is a zero-knowledge proof that you know your private key, associated with some metadata.
- mabbo 5y ago> Say one can send the exact cryptographic fingerprint and impersonate me. How is this anything better than me just sending password to authenticate? If you're genuinely interested in this topic, you will, I think, really enjoy what I'm about to tell you. You can setup a system where: 1- you never tell the server your plaintext password at any time, ever; 2- the server does not know your actual password and cannot determine it; 3- you can prove to the server that you know the password, and they have strong proof that you do know it; 4- nobody that eavesdrops on you can do likewise. Cryptography is magic. And it mostly has to do with the authentication protocol being multi-step. IE: you don't just send your password or fingerprint, you send X and the server sends back Y, and you send Z, and so on and so on, but after a few steps, you have proven yourself. And since it's all being done on GHZ speed computers and gbps networks, it's fast enough for human use. There are better algorithms than this one, evolutions on the idea, but the most common one discussed is Secure Remote Password Protocol: https://en.wikipedia.org/wiki/Secure_Remote_Password_protocol https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco... And honestly, I'm not even doing justice to how cool these protocols are. It's an incredible topic.
- ben-ray 5y ago> Say one can send the exact cryptographic fingerprint and impersonate me. How is this anything better than me just sending password to authenticate? The message can be signed with a private key to ensure you are not being impersonated. In cases where you'd also like anonymity, it is possible to add some salt as an input to the 'cryptographic fingerprint,' obfuscating the unsalted proof. This video is good material for learning to reason about ZK proofs: https://www.youtube.com/watch?v=J3UlqJk3Kl0 https://www.youtube.com/watch?v=J3UlqJk3Kl0
- hanniabu 5y ago> you can simply send a proof My bank doesn't even support OTP 2FA for login. There's no way they'll support this stuff.