[saag] TOTP Secure Enrollment - HotRFC discussion

Brian Contario <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAFdCCzhUvkuA0s6AUODgn3NGd67vim0ufnAoLKLH9v47Z+OTHA@mail.gmail.com>
Hi all,

There is a SEC related lightning talk in the HotRFC session tonight
18:00-20:00 at IETF 124

The talk covers a draft to eliminate exposing the non-expiring secret key
in the QR code enrollment process of the common Time-based One Time
Password process used for MFA.

We can reply to this email thread for comments and collaborations.

Here is the I-D:
https://datatracker.ietf.org/doc/draft-contario-totp-secure-enrollment/

Here is a PDF of the lightning talk slides:
https://silent-sector.github.io/totp-secure-enrollment/HotRFC_TOTP_Secure_Enrollment_v2.pdf

Thanks!
Brian Contario

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.