GRC's | SQRL Secure Quick Reliable Login
So it has some functions like a password manager, but the usability is interesting.
SQRL  login  authentication  cryptography  QRcode  security 
6 days ago by asteroza
FIDO Alliance Biometric Component Certification Program - FIDO Alliance
New industry standards for biometric security certification, for FIDO biometric security. Kinda nice that there's an industry standard of sorts...
biometric  security  certification  standard  FIDO  authenticator  authentication  face  finger  recognition 
november 2018 by asteroza
Colm MacCárthaigh on Twitter: "Client certs and Mutual-Auth TLS is TERRIBAD."
I never really thought deep about client certs, but this makes a real case for why they actually suck, and possibly suck worse than anything else before...
client  certificate  TLS  MTLS  mutual  authentication  security  layer  violation 
october 2018 by asteroza
FIDO ®-Multi-Interface | FEITIAN
Looks like google's new Titan security key is an OEM Feitian multi, but allegedly with google built firmware (because Feitian firmware has had issues in the past...)
google  titan  USB  U2F  FIDO  NFC  BLE  bluetooth  security  key  hardware  electronics  devices  2FA  OTP  TOTP  authentication 
july 2018 by asteroza
paragonie/paseto: Platform-Agnostic Security Tokens
This is a more general token rather than as an alternative for JWT for JWT specific use cases. Though most JWT could be covered by a cookie better...
authentication  token  software  opensource  stateless  security  alternative  JWT 
june 2018 by asteroza
Web Authentication: An API for accessing Public Key Credentials Level 1
Improved web authentication on browsers using external USB/bluetooth/NFC security tokens, namely YubiKey.
WebAuthn  authentication  specification  standard  FIDO  U2F  webdev  security  web  external  hardware  token  access 
april 2018 by asteroza
ID4me – One ID for everything, everywhere
Dovecot makers are planning to extend IMAP to realtime chat, but need a federated ID backend using domain names. Looks like they will implement this through PowerDNS and this spec/group
ID4me  federated  ID  authentication  identity  backend  standard  specification  realtime  chat  IM  IMAP  dovecot  PowerDNS 
march 2018 by asteroza
Keratin AuthN
Based on Oauth, but API driven rather than redirect driven so you can customize your UX more
go  authentication  library  OAuth  microservice  authorization  webdev  programming  development  security 
november 2017 by asteroza
USB Dongle Auth List
List of sites with support for USB dongle authentication which includes One Time Passwords (OTP) and Universal 2nd Factor (U2F).
website  support  OTP  FIDO  U2F  list  compatibility  reference  information  USB  dongle  yubikey  security  password  authentication  2FA 
november 2017 by asteroza
B-Unit | Bloomberg Professional Services
A sort of beefed up FIDO U2F device, but with higher hardware protection features. Uses a photoreceptor to receive codes from the terminal screen itself, so no NFC/bluetooth/USB
bloomberg  terminal  authentication  portable  private  key  token  hardware  electronics  devices  security 
november 2017 by asteroza
A specification and reference implementation of a framework for secure distributed identity provisioning. Intended for short lived certs between microservices for mutual TLS authentication, but should be usable for other identity scenarios...
microservice  identity  framework  security  software  PKI  certificate  authentication  TLS  short  lived 
october 2017 by asteroza
gravitational/teleport: Modern SSH server for clusters and teams.
Interesting authentication proxy/SSH bastion host software, for allowing distributed teams to safely access distributed resources
SSH  bastion  host  authentication  proxy  SSO  cloud  management  devops  kubernetes  security  certificate  sysadmin  software 
september 2017 by asteroza
2STP Authenticator on the App Store
Good TOTP authenticator with reasonable backup/export options for phone migration
iPhone  iOS  app  authentication  HOTP  TOTP  OTP  authenticator  software  security  Delicious 
february 2017 by asteroza
DRAFT NIST Special Publication 800-63B
NIST now saying forced periodic password changes are stupid, and password max length is also stupid.
NIST  password  security  digital  authentication  government  guideline  reference  information  draft  Delicious 
july 2016 by asteroza
Demoing a stereo jack based FIDO U2F external auth token for smartphones
FIDO  U2F  external  authentication  token  stereo  jack  hardware  electronics  devices  encryption  security  Delicious 
march 2016 by asteroza
Nok Nok Labs, Inc.
supposedly made a third party API bridge for using iPhone fingerprint sensors for two factor security.
2FA  two  2  factor  authorization  authentication  smartphone  phone  app  software  token  security  oauth  fingerprint  Delicious 
december 2014 by asteroza
Interesting alternative to NFC touchless comms, particularly for authentication/payment systems
NearBytes  acoustic  communication  protocol  proximity  short  range  ultrasonic  audio  sound  smartphone  android  iPhone  windows  app  software  authentication  side  channel  Delicious 
june 2014 by asteroza
Press Releases : DOCOMO Develops World's First SIM-based Authentication Mini Device
This isn't totally insane, as many countries are moving to electronic ID's using touchless access already. Moving some of the functionality to a bracelet that can be reused for SIM attributes is a reasonable extension of this concept. bluetooth fundamentally supports a remote SIM access profile, which is basically an extension of serial interface profiles already. Anything above SIM profile access though may be problematic without reusing an existing profile or standardizing a new one.
NTT  DoCoMo  research  portable  SIM  bracelet  authentication  external  storage  ID  touchless  bluetooth  Delicious 
june 2014 by asteroza
Using a blockchain concept to get over the PGP key directory server hump.
security  blockchain  keychain  identity  authentication  key  PKI  directory  cryptography  PGP  SSH  GPG  Delicious 
april 2014 by asteroza
