GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    arcanicanis (arcanicanis@were.social)'s status on Saturday, 14-Jan-2023 13:14:48 JSTarcanicanisarcanicanis
    in reply to
    • Coyote
    • silverpill
    For USB token auth, it's just an HID device that communicates using the CTAP protocol to serialize requests/responses, so there's not much capacity for it to talk to the outside world, unless you fabricate some RF-emitting component inside the token to transmit to some auxiliary wireless network to exfiltrate that information. It's just a very opinionated standard of public key authentication, anyone's free to implement hardware as they so choose.

    My interest in it is solely for hardware-backed authentication, versus private keys that are resident within your filesystem or RAM (such as when a private key is unwrapped). You can also use a token for SSH public key auth for cheap.

    Of course it still falls into a matter of trust of the hardware vendor, but that's also the same dilemma but on a much wider scale with most desktop computing hardware.

    Nonetheless, as stated: my interest is for USB token authentication, used as a second-factor of authentication. I'm questionable in some areas, such as using a smartphone as a single-factor authenticator (regardless of whether it has it's own isolated hardware cryptographic component). I only advocate for it within the former profile. There's also the standard itself which is openly documented and inspectable (especially in the device communication), and if it starts to get shoved in the wrong usage, then of course that's time to raise hell if any of the larger orgs steer adoption in the wrong direction.
    In conversationSaturday, 14-Jan-2023 13:14:48 JST from were.socialpermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.