#IETF #RFC #openSource #programming #totp #hotp
#xsukax Secure #Authenticator
https://github.com/xsukax/xsukax-Secure-Authenticator
Demo: https://xsukax.github.io/xsukax-Secure-Authenticator/
A privacy-focused, #client-side #two-factor authentication (2FA) application that generates Time-based One-Time Passwords (TOTP) and #HMAC-based One-Time Passwords (HOTP) entirely within your browser. No server communication, no tracking, complete control over your authentication codes.
@sushimcpe I guess #Microsoft does bespoke things (like #Fortinet) instead of existing Standards like #TOTP & #HOTP…
918273 ?Given that there are more attacks than yesterday, I presume that my personal research is successful. 😋
Last week I started wondering whether #HOTP #MFA (and by extension TOTP) are #zeroknowledge #zeroknowledgeproof. I couldn't find an immediate answer, but even more, there were very few results combining these two topics. So I did my own research and evaluation.
https://dannyvanheumen.nl/post/analysis-are-hotp-zero-knowledge-proofs/
I have posted the initial version for the analysis on 'are #HOTP #zeroknowledge proofs'.
Although the blog post is not very mathematical in nature, I seem to have covered all relevant aspects. Previous social media posts covered the gist, but there is more detail present in the blog post.
https://dannyvanheumen.nl/post/analysis-are-hotp-zero-knowledge-proofs/
Intuitive explanation for #zeroknowledge #zeroknowledgeproof analysis for #HOTP #MFA principle.
@sleepybisexual also anything but #TOTP & #HOTP is just garbage.
@dalias nodds in agreement...
I can understand it for #business #communications and all the crappy #SaaS corporations use to keep their shit up and running.
Like #GitHub, #Slack, #GoogleWorkspace and all that cringe.
I can see why they want to push for #2FA and have #business customers mandate that for accounts cuz "#CheckboxSecurity" and stuff...
Worst when #2FA doesn't allow #privacy-friendly options like TANs and/or #TOTP / #HOTP but demand #PII like a #PhoneNumber!
@ohno_itsnate @GrapheneOS I recommend looking at #TOTP & #HOTP for #2FA.
As for devices, I can vouch for @nitrokey !