4 ms·
I'm currently experimenting with Ed25519 signatures in place of passwords for website authentication: Git repo: https://github.com/62726164/ed25519-login https
by _wldu 5y ago
I'm currently experimenting with Ed25519 signatures in place of passwords for website authentication:
Git repo: https://github.com/62726164/ed25519-login https://github.com/62726164/ed25519-login
Test website: https://gen.go350.com/ https://gen.go350.com/
I plan to write an Android and iOS app (someday) that has the same functionality as ed25519-login. We need to go password less, but the complexity of webauthn is too much IMO.
I'm looking for feedback and appreciate any suggestions.
- Grimburger 5y agoTLS already has client side authentication baked in, it's just that no one really uses it or even knows it exists. Most (all?) browsers support it. https://aboutssl.org/ssl-tls-client-authentication-how-does-it-works/ https://aboutssl.org/ssl-tls-client-authentication-how-does-...
- _wldu 5y agoYes. Mutual TLS. But that involves certificates, potentially CAs, dealing with certificate expirations and other PKI formalities. Any user can generate an Ed25519 key pair, base64 encode the public part of the key and register that with websites. It's more informal than TLS certificates and totally user controlled. I do use TLS client certificates (with several APIs) but I don't consider them as password replacements (which is the goal of ed25519-login).
- dyml 5y agoI agree that WebAuthn is complicated (I’ve read the W3C spec more times than I care to admit). Disclaimer: I maintain an open source FIDO2 library. However WebAuthn has the might of device-, OS and browser makers behind it which improves the chances of wide adoption and “what users will expect”-rate. For those who do not want to understand all the complexity, but still leverage high security and “fingerprint / faceid” sign in on their web app we created passwordless.dev. It’s a very easy way to try out and implement webauthn in your project. Happy to help fokes get started if you’re interested! You can get your API key or run the demo on: https://passwordless.dev https://passwordless.dev