6 ms·
I don't know how much they overlap, but Steve Gibson was saying recently in one of this latest Security Now podcasts that what FIDO is trying to do is inferior
by salient 13y ago
I don't know how much they overlap, but Steve Gibson was saying recently in one of this latest Security Now podcasts that what FIDO is trying to do is inferior to his recently launched SQRL protocol. He starts talking about it at 0:56:
http://twit.tv/show/security-now/435 http://twit.tv/show/security-now/435
He says the FIDO spec is overdesigned, and everyone there has their own interests, it's tied to certain technologies, and it's not free. SQRL on the other hand generates the keys on the fly instead of storing them on the phone for each website. If a hacker steals your identity, you can also get it back with SQRL - you can't with FIDO. He says SQRL is also much easier to implement.
https://www.grc.com/sqrl/sqrl.htm https://www.grc.com/sqrl/sqrl.htm
http://www.sqrl.pl/ http://www.sqrl.pl/ (fan-made)
Also, an interesting excerpt from Wikipedia, referring to when he announced the protocol for the first time:
> Within 2 days of the airing of this podcast, both the W3C and Google expressed interest in working on the standard.[2]
http://en.wikipedia.org/wiki/SQRL http://en.wikipedia.org/wiki/SQRL
- devinegan 13y agoThe SQRL idea could certainly be implemented under FIDO and he doesn't seem to make that distinction. FIDO is a platform for integrating many authentication technologies/companies/standards. It is a shared layer that biometrics, devices, etc can plug in to and authenticate. There is WAY more choice. For instance, company X might want to use a SQRL solution. If it is FIDO compliant they could use SQRL anywhere FIDO authentication is available. This could now include Microsoft software and properties. It is unlikely that SQRL would ever be directly supported by Microsoft. FIDO is possibly the way in.
- guard-of-terra 13y agoThe scheme you are describing (a lot of vaguely integrated layers from different suppliers/standards) has never worked in my memory. It inflicted tons of pain and suffering and then never delivered anything usable. You really need common functional denominator in order this to fly.
- hamburglar 13y ago"Steve Gibson was saying recently in one of this latest Security Now podcasts that what FIDO is trying to do is inferior to his recently launched SQRL protocol" Of course he was. He's Steve Gibson. He's a shameless self-promoter and he loves to make over-dramatic claims of finding security flaws in things. His only saving grace is that SQRL actually looks pretty sound to my moderately-better-than-amateur security experience. I hate to admit it, because if it catches on as a standard, he's only going to become more insufferable. The guy is a kook, except he's a kook who maybe have actually done his homework this time. I'd still like to hear what some actual security researchers have to say about SQRL, because I'm sure as hell not going to take his word on it.
- ay 13y ago+1 on all counts. I went to Wikipedia page and looks like it was written if not by him then by his fans - it does not contain a half decent description of the protocol. Just some propaganda-like fluff. I admit "squirrel" does sound cool. But how is it different from any other challenge-response algorithm escapes me.
- guard-of-terra 13y agoFor example it might become different from other algorithms because it will be working and solving users' problems instead of just existing in abstract algorithm-land?