[saag] Re: Review requested - draft-contario-totp-secure-enr ollment-00
Brian Contario <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CAFdCCzgYmdjAiOgo84rzNBppxQt3nbRz=xEk7RqDAYaO-+uWFQ@mail.gmail.com> |
Hi Simon and ilteriş, Thank you both for your feedback. > 1) This depends on the widely deployed otpauth:// URI scheme, and I was > happy to notice that you found a I-D specifying it. Would you and/or > Ilteris be interested in moving this document forward? I think it is a > long missing work that underpins many OATH-related deployments. Maybe > we can all help improve the base otpauth:// URI specification. I am new to the draft process, so will be watching the URI spec draft closely and contribute as I can, especially if submitting to secdispatch@ is the next step after comments are addressed. > 2) Could you extend your document to support HOTP and/or CROTP? There is nothing that would prevent the same process from being used by other MFA enrollments, but I cannot find any information on CROTP, and if the authenticator app supports TOTP it is likely to support the same QR code enrollment for HOTP with the same URI. I have never had to enroll in HOTP or use it or support it in IT, so the benefit may be limited. > 3) The Security Considerations ought to mention that blindly downloading > URLs embedded in QR codes may open up for user and application behaviour > fingerprinting. To be honest, I think this may cause some implementers > to walk away from implementing it. Could you explain more about the concern? The URI in the QR code has to meet a very specific format pattern before the app will extract the URL and request the text payload that is then expected to match the original TOTP URI format, so blindly downloading URLs from a normal QR code can not happen. 4) Expand acronyms like OATH and TOTP. TOTP is expanded in both the Abstract and the Terminologies section. Should it also be expanded in the Introduction, or other places as well? Thank you! Brian On Sun, Feb 16, 2025 at 5:54 PM İlteriş Yağıztegin Eroğlu < [email protected]> wrote: > Hi Simon, > > > This depends on the widely deployed otpauth:// URI scheme, and I was > > happy to notice that you found a I-D specifying it. Would you and/or > > Ilteris be interested in moving this document forward? > > I was actually thinking to send the URI spec draft to secdispatch@ after > a long while of neglect so I'll be more than happy to move it forward. > > Also Brian, that's an interesting implementation! And I also agree with > Simon's improvement ideas. > > -ilteriş _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]