Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror

Comment Millennial (Score 0) 70

âoe humorously heavy and bulky older cathode-ray tube (CRT) TVs that used to populate family roomsâ - written like a true millennial who now feels super high tech with their 100-inch flat screen - bet theyâ(TM)ll feel awkward in 20 years when the same comment is made about physical screens and how hilarious they were compared with beaming images direct into the brain. Be humble and recognize technology within its historical context.

Comment Re: Where are you going to plug it in? (Score 1) 106

Modern keys support nfc for contactless verification. Also, the phone itself can be used as an authentication device, with the private key residing in the phoneâs TPM and unlocked by biometrics (fingerprint or face scan).

The solution is technically unsound for other reasons but the authentication bits of it actually work almost anywhere nowadays.

Comment Fido2 is not tied to hardware (Score 2) 106

Fido2 and webauthn are protocols, nothing in them dictates the device has to be a physical key. Itâ(TM)s possible to implement the entire thing in software which totally nullifies the concept behind this. Iâ(TM)m actually surprised the idiots as cloud flare havenâ(TM)t foreseen this possibility.

I mean, of course the webauthn request can specify it requires a hardware key (which translates to biometrics-unlocked TPM if youâ(TM)re using a mobile device that supports that) but this is enforced by the browser, and given enough motivation someone could modify the browsers code so it ignores that requirement and just returns a signed reply automatically. No human involved

This is a terrible idea but it probably doesnâ(TM)t matter because itâ(TM)s technically wrong so will probably fail on its own.

Slashdot Top Deals

"An organization dries up if you don't challenge it with growth." -- Mark Shepherd, former President and CEO of Texas Instruments

Working...