[saag] Re: Review requested - draft-contario-totp-secure-enr ollment-00

Brian Contario <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CAFdCCzgYmdjAiOgo84rzNBppxQt3nbRz=xEk7RqDAYaO-+uWFQ@mail.gmail.com>
Hi Simon and ilteriş,

Thank you both for your feedback.

> 1) This depends on the widely deployed otpauth:// URI scheme, and I was
> happy to notice that you found a I-D specifying it.  Would you and/or
>   Ilteris be interested in moving this document forward?  I think it is a
>   long missing work that underpins many OATH-related deployments.  Maybe
>   we can all help improve the base otpauth:// URI specification.

I am new to the draft process, so will be watching the URI spec draft
closely and contribute as I can, especially if submitting to secdispatch@
is the next step after comments are addressed.

> 2) Could you extend your document to support HOTP and/or CROTP?

There is nothing that would prevent the same process from being used by
other MFA enrollments, but I cannot find any information on CROTP, and if
the authenticator app supports TOTP it is likely to support the same QR
code enrollment for HOTP with the same URI.  I have never had to enroll in
HOTP or use it or support it in IT, so the benefit may be limited.

> 3) The Security Considerations ought to mention that blindly downloading
> URLs embedded in QR codes may open up for user and application behaviour
> fingerprinting.  To be honest, I think this may cause some implementers
> to walk away from implementing it.

Could you explain more about the concern?  The URI in the QR code has to
meet a very specific format pattern before the app will extract the URL and
request the text payload that is then expected to match the original TOTP
URI format, so blindly downloading URLs from a normal QR code can not
happen.

4) Expand acronyms like OATH and TOTP.

TOTP is expanded in both the Abstract and the Terminologies section.
Should it also be expanded in the Introduction, or other places as well?

Thank you!
Brian


On Sun, Feb 16, 2025 at 5:54 PM İlteriş Yağıztegin Eroğlu <
[email protected]> wrote:

> Hi Simon,
>
> > This depends on the widely deployed otpauth:// URI scheme, and I was
> > happy to notice that you found a I-D specifying it.  Would you and/or
> > Ilteris be interested in moving this document forward?
>
> I was actually thinking to send the URI spec draft to secdispatch@ after
> a long while of neglect so I'll be more than happy to move it forward.
>
> Also Brian, that's an interesting implementation! And I also agree with
> Simon's improvement ideas.
>
> -ilteriş

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.