[saag] Re: Review requested - draft-contario-totp-secure-enr ollment-00
Simon Josefsson <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Hi, I've read this and think it is nice work, some comments: 1) This depends on the widely deployed otpauth:// URI scheme, and I was happy to notice that you found a I-D specifying it. Would you and/or Ilteris be interested in moving this document forward? I think it is a long missing work that underpins many OATH-related deployments. Maybe we can all help improve the base otpauth:// URI specification. https://datatracker.ietf.org/doc/html/draft-linuxgemini-otpauth-uri-01 2) Could you extend your document to support HOTP and/or CROTP? 3) The Security Considerations ought to mention that blindly downloading URLs embedded in QR codes may open up for user and application behaviour fingerprinting. To be honest, I think this may cause some implementers to walk away from implementing it. 4) Expand acronyms like OATH and TOTP. /Simon Brian Contario <[email protected]> writes: > Greetings all. > > I am working on a draft that describes a secure enrollment method for > commonly-used multifactor authentication applications using the Time-Based > One-Time Password (TOTP) algorithm. Since RFC6238 describes the algorithm, > but not the enrollment process, the enrollment process appears to have > evolved focused on ease-of-use rather than security. This draft proposes a > method to prevent compromise of the non-expiring TOTP key embedded in the > QR code used for enrollment which can be photographically captured or > persisted in email, SMS, or other systems to later be harvested by an > attacker. > > Please consider reviewing the current draft > https://datatracker.ietf.org/doc/draft-contario-totp-secure-enrollment/ > and posting your feedback to this mailing list. > > Thank you in advance for your consideration and assistance, > Brian > _______________________________________________ > saag mailing list -- [email protected] > To unsubscribe send an email to [email protected] > _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE----- iQNoBAEWCAMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmeyZGwUHHNpbW9uQGpv c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh BLHSvRN1vst4TPT4xNc89jjFPAa+BQJl/YgIBQkLehFUAAoJENc89jjFPAa+CboA +wUa06RD5e5VTCxvSWtPS75Wq2qBeYGZnf0jvUMxa2n4AP4xkUeAPPnNuMsTm2fs FCDIGaEM2Yn6Vb2huzzT1Fw/BLgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0 +MTXPPY4xTwGvgUCZf2IKwUJC3oQqgCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE 8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J ENc89jjFPAa+GcYA/26YQY05bLtnXiIjTiAzrGQrRXxTHPA8Av7TDFHvIetWAP9s HSoU8OfTwmTiEnGwLlsV7QJclZg3YNz/Ypcp9TqQBrg4BFySz2oSCisGAQQBl1UB BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJl/YgwBQkLehDGAAoJENc89jjF PAa+phoA/jrDqIrl/55vUMBhIQv+TP635d2iCTEnyFmbUcP9+gh6APoDsXalVd2c OGxQtSC+TF8PkZMn1TLkJKAjVxr+xx40AgAKCRBRcisI/kdFogtpAQCJQLtYsmhx K1SYwHWJR1NFdRJ5pM71SAbnLlyREl98kQD/TCelCptIGwImKayfSx4HjoXf6Gog QnJd8v9VRld0awQ= =q4ZM -----END PGP SIGNATURE-----