4 ms·
Care to expand on this a bit? I'm somewhat familiar with SQRL, but what was this IP binding proposal all about? Is this a use-case not discussed in the SQRL ph
by themattrix 12y ago
Care to expand on this a bit? I'm somewhat familiar with SQRL, but what was this IP binding proposal all about?
Is this a use-case not discussed in the SQRL phishing page?
https://www.grc.com/sqrl/phishing.htm https://www.grc.com/sqrl/phishing.htm
- nly 12y agoIt's there buried in the discussions somewhere. The basic (and old) idea is to shove the IP of the user (or spoof as the case may be), as seen by the web server, in to the QR code and then tie it to with the session token using a MAC. When the SQRL app passes the signed SQRL data back to the web server it passes this back as well. The server can then reverify the users IP (remember they're now using the app on another device). IP binding is worth doing but there's no way for the app to warn the user that the IP differs. You have to trust the server implementation of SQRL (which despite what Gibson claims, is actually fairly complex on the server-side) Other issues are discussed on the page you linked entitled "Details and Limitations of IP-based MITM detection"