3 ms·
you've essentially described what google is trying to do with gnubby/u2f, now hamstrung by FIDO and converging UAF standards. If you are interested a high level
by rmac 11y ago
you've essentially described what google is trying to do with gnubby/u2f, now hamstrung by FIDO and converging UAF standards. If you are interested a high level explanation is here: https://docs.google.com/presentation/d/16mB3Nptab1i4-IlFbn6vfkWYk-ozN6j3-fr7JL8XVyA/edit#slide=id.g19c09a112_2_0 https://docs.google.com/presentation/d/16mB3Nptab1i4-IlFbn6v...
the idea being you mint a new keypair per service and the private keys are stored securely on your device (currently yubikeys but soon all devices will have a secure way to store key material (e.g., secure enclave, TEE, secure elements)), public keys get stored on the service you want to authenticate against.