[saag] Re: Review requested - draft-contario-totp-secure-enr ollment-00

Simon Josefsson <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Hi,

I've read this and think it is nice work, some comments:

1) This depends on the widely deployed otpauth:// URI scheme, and I was
happy to notice that you found a I-D specifying it.  Would you and/or
Ilteris be interested in moving this document forward?  I think it is a
long missing work that underpins many OATH-related deployments.  Maybe
we can all help improve the base otpauth:// URI specification.

https://datatracker.ietf.org/doc/html/draft-linuxgemini-otpauth-uri-01

2) Could you extend your document to support HOTP and/or CROTP?

3) The Security Considerations ought to mention that blindly downloading
URLs embedded in QR codes may open up for user and application behaviour
fingerprinting.  To be honest, I think this may cause some implementers
to walk away from implementing it.

4) Expand acronyms like OATH and TOTP.

/Simon

Brian Contario <[email protected]> writes:

> Greetings all.
>
> I am working on a draft that describes a secure enrollment method for
> commonly-used multifactor authentication applications using the Time-Based
> One-Time Password (TOTP) algorithm.  Since RFC6238 describes the algorithm,
> but not the enrollment process, the enrollment process appears to have
> evolved focused on ease-of-use rather than security.  This draft proposes a
> method to prevent compromise of the non-expiring TOTP key embedded in the
> QR code used for enrollment which can be photographically captured or
> persisted in email, SMS, or other systems to later be harvested by an
> attacker.
>
> Please consider reviewing the current draft
> https://datatracker.ietf.org/doc/draft-contario-totp-secure-enrollment/
> and posting your feedback to this mailing list.
>
> Thank you in advance for your consideration and assistance,
> Brian
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE-----

iQNoBAEWCAMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmeyZGwUHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJl/YgIBQkLehFUAAoJENc89jjFPAa+CboA
+wUa06RD5e5VTCxvSWtPS75Wq2qBeYGZnf0jvUMxa2n4AP4xkUeAPPnNuMsTm2fs
FCDIGaEM2Yn6Vb2huzzT1Fw/BLgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCZf2IKwUJC3oQqgCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+GcYA/26YQY05bLtnXiIjTiAzrGQrRXxTHPA8Av7TDFHvIetWAP9s
HSoU8OfTwmTiEnGwLlsV7QJclZg3YNz/Ypcp9TqQBrg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJl/YgwBQkLehDGAAoJENc89jjF
PAa+phoA/jrDqIrl/55vUMBhIQv+TP635d2iCTEnyFmbUcP9+gh6APoDsXalVd2c
OGxQtSC+TF8PkZMn1TLkJKAjVxr+xx40AgAKCRBRcisI/kdFogtpAQCJQLtYsmhx
K1SYwHWJR1NFdRJ5pM71SAbnLlyREl98kQD/TCelCptIGwImKayfSx4HjoXf6Gog
QnJd8v9VRld0awQ=
=q4ZM
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.