[saag] Re: TOTP Secure Enrollment - HotRFC discussion
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <2276233.1762181150@dyas> |
Brian Contario <[email protected]> wrote: > There is a SEC related lightning talk in the HotRFC session tonight > 18:00-20:00 at IETF 124 > The talk covers a draft to eliminate exposing the non-expiring secret > key in the QR code enrollment process of the common Time-based One Time > Password process used for MFA. Are you doing SECDISPATCH? I see why this update to RFC6238 is coming to the IETF. RFC6238 went through as AD sponsor I think. But, the QR code mechanism is not part of 6238, and I don't really know who, if anyone owns that. Fixing this seems like a good thing, but do you have critical quorum of users/scanners of the QR code to make this deployable. Suppliers of of TOTP QR codes can upgrade only after the client side has become ubiquitous. The I-D very correctly writes: A fallback method of showing the key string to be typed or copied and pasted into a multi-factor authenticator application also exposes the key. In both cases the key that is exposed is the permanent shared TOTP secret key that, by current standards and processes, is expected to never expire. For some of us, this is kind of a feature... Print to treeware as backup ;-) (Power cycle printer afterwards. My printer has no hard drive. NSFW!) -- Michael Richardson <[email protected]>, Sandelman Software Works -= IPv6 IoT consulting =- *I*LIKE*TRAINS* _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEERK+9HEcJHTJ9UqTMlUzhVv38QpAFAmkIwB4ACgkQlUzhVv38 QpC0hAf+OYrLV3t9sXWi6zgzrWkfjDJoM4x4zYiwkdSQuvxlrTN23R7m2FthqpXL 3SkHiyT74Bd0dJ5drLnM24fRD6K6ca/FSPoqHUK08x1XjVAtVIrmvFt9GW8gMIwm H846pN20RdoH+EpryjkpgxnFmH1U91u+uKJPAsFHhZyQ9bj/IV0WA7FbMEyBaMUr 80ChV4KgxuW8lzsL6btdzDBYkw0l9c/KyFQkpJMpMN/Cb29AWOeUVK9O4Iyq3Mpq 6Cnn3tpN+Okn+h9l+apusvQncnM5SxaH+xGqDkX1eS9LygnUMZXIh1pJeJigV43q bSf8Jnak+Vwl936iaJwLk2IgWbbXHA== =KBRR -----END PGP SIGNATURE-----