[saag] Review requested - draft-contario-totp-secure-enrollmen t-00
Brian Contario <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CAFdCCzjW1Q=fSSLek83vM00AWF5XR7aFddo4f2i5Rmww_8AReg@mail.gmail.com> |
Greetings all. I am working on a draft that describes a secure enrollment method for commonly-used multifactor authentication applications using the Time-Based One-Time Password (TOTP) algorithm. Since RFC6238 describes the algorithm, but not the enrollment process, the enrollment process appears to have evolved focused on ease-of-use rather than security. This draft proposes a method to prevent compromise of the non-expiring TOTP key embedded in the QR code used for enrollment which can be photographically captured or persisted in email, SMS, or other systems to later be harvested by an attacker. Please consider reviewing the current draft https://datatracker.ietf.org/doc/draft-contario-totp-secure-enrollment/ and posting your feedback to this mailing list. Thank you in advance for your consideration and assistance, Brian _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]