[saag] Re: TOTP Secure Enrollment - HotRFC discussion

Michael Richardson <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <2276233.1762181150@dyas>
Brian Contario <[email protected]> wrote:
    > There is a SEC related lightning talk in the HotRFC session tonight
    > 18:00-20:00 at IETF 124

    > The talk covers a draft to eliminate exposing the non-expiring secret
    > key in the QR code enrollment process of the common Time-based One Time
    > Password process used for MFA.

Are you doing SECDISPATCH?
I see why this update to RFC6238 is coming to the IETF.
RFC6238 went through as AD sponsor I think.

But, the QR code mechanism is not part of 6238, and I don't really know who,
if anyone owns that.   Fixing this seems like a good thing, but do you have
critical quorum of users/scanners of the QR code to make this deployable.
Suppliers of of TOTP QR codes can upgrade only after the client side has
become ubiquitous.

The I-D very correctly writes:
   A
   fallback method of showing the key string to be typed or copied and
   pasted into a multi-factor authenticator application also exposes the
   key.  In both cases the key that is exposed is the permanent shared
   TOTP secret key that, by current standards and processes, is expected
   to never expire.

For some of us, this is kind of a feature... Print to treeware as backup ;-)
(Power cycle printer afterwards.  My printer has no hard drive. NSFW!)

--
Michael Richardson <[email protected]>, Sandelman Software Works
 -= IPv6 IoT consulting =-                      *I*LIKE*TRAINS*

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEERK+9HEcJHTJ9UqTMlUzhVv38QpAFAmkIwB4ACgkQlUzhVv38
QpC0hAf+OYrLV3t9sXWi6zgzrWkfjDJoM4x4zYiwkdSQuvxlrTN23R7m2FthqpXL
3SkHiyT74Bd0dJ5drLnM24fRD6K6ca/FSPoqHUK08x1XjVAtVIrmvFt9GW8gMIwm
H846pN20RdoH+EpryjkpgxnFmH1U91u+uKJPAsFHhZyQ9bj/IV0WA7FbMEyBaMUr
80ChV4KgxuW8lzsL6btdzDBYkw0l9c/KyFQkpJMpMN/Cb29AWOeUVK9O4Iyq3Mpq
6Cnn3tpN+Okn+h9l+apusvQncnM5SxaH+xGqDkX1eS9LygnUMZXIh1pJeJigV43q
bSf8Jnak+Vwl936iaJwLk2IgWbbXHA==
=KBRR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.