Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
_pzht
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
_pzht
5y ago
I like the idea of signing a nonce rather than the current time. That solves several problems. Thanks for the advice.
2.
▲
by
_pzht
5y ago
Used signatures are purged from the DB after they are no longer valid (too much time has passed). I realize this is a naive, toy implementation (in general). I wrote it to have a broader discussion.
3.
▲
by
_pzht
5y ago
Because it was in reply to my earlier comment saying this is not SSO. People seem to think these signatures can be used on multiple websites (sign in with Google like functionality). That's not the case. These signatures are meant to b
4.
▲
by
_pzht
5y ago
The demo website and the github repo contain this information. It would be helpful, if people actually created a key pair and tried to use it and misuse it before being critical. It's not meant for federation, single-sign on (which is
5.
▲
by
_pzht
5y ago
Users can have a different key pair for each website. Also, signatures may not be re-used and are only valid for a few seconds. Try to create a key pair and login to the test website.
6.
▲
by
_pzht
5y ago
This is not meant for SSO. Signatures are only valid for about 30 - 60 seconds (depending on the server config) and may not be re-used after a successful login. Try to create a key pair and log into the test website. Then try to use the sam
7.
▲
by
_pzht
5y ago
The web service stores used signatures. They cannot be re-used and are only good for about 30 seconds. Try to register on the demo site and see if you can actually replay a signature.
8.
▲
Login with a Public Ed25519 Key
(github.com)
97 points
by
_pzht
5y ago
|
81 comments