3 ms·
This is a very cool concept, however, (from the site:) > Can I see the source code? > Sure! Bulwark Passkey is built on top of an open source core called Vir
by fire 4y ago
This is a very cool concept, however,
(from the site:)
> Can I see the source code?
> Sure! Bulwark Passkey is built on top of an open source core called Virtual FIDO, which contains the USB emulation and FIDO protocol code, as well as the credential encryption and formatting. You can view the safety critical parts of the code, as well as easily decrypt and transfer your credentials out of the system.
So... it... isn't? It sounds like it isn't.
Like, maybe I'm just paranoid at this point, but regardless of how exciting this is in concept, I'm not too keen on using an (unaudited) virtual replacement for a hardware security token when I can neither audit the app I'm actually running, nor (preferably) build it from source; More generally, how would I even tell that the library in use by the app as-built is the same as the source on github?
- cmdli 4y agoThat's a fair point. I would like to have the entire thing be open source for security purposes like you mentioned, but right now the frontend is built with TailwindUI, which is a paid set of components, so I was worried about open sourcing that up front. I will take a closer look at how to open source it, especially the parts that would be security critical. I do agree with the general policy of not trusting security devices you can't audit yourself (which is why I opened up the core library earlier).
- unqueued 4y agoThis is a really cool product! I'm so glad someone is finally trying to solve this problem. Not having control of your secrets is a big problem. It is why I continue to use TOTP for some things. Maybe lean into the practical problem this solves and how it empowers the user? I am going to suggest this to people. But I feel like I'd have to explain to them what it does, and why it is cool. I remember a few years ago when Keybase took off a few years ago. I think Keybase did a pretty good job of presenting itself to it's audience. I know plenty of people who understand what a Yubikey is, but might not understand what this app is. Personally, I love that I could keep backups of my TOTP secret keys in encrypted qr codes on paper in a safe, if I wanted to. I think it is deeper than just the technical part of it. I think people really like anchoring their accounts to something that they can "see". It would be really easy to let you import and export your secrets to physical media. And there are some interesting options with chaining your secrets to other hardware tokens (that you are in control of). Of course it gets very tricky when suggesting anything security related. I don't want to tell people that they shouldn't use hardware tokens. But I think that relying on hardware tokens can be really inaccessible, which can itself be make a system less secure. Best of luck!
- cmdli 4y agoSo, I look a closer look and it seems like TailwindUI does allow for building open source software, so I made the Bulwark Passkey repo public (https://github.com/bulwarkid/bulwark-passkey https://github.com/bulwarkid/bulwark-passkey) if you wanted to take a look!