PSA for those implementing #rfc6238: READ THE ERRATA! Maybe even before reading the RFC itself. I wasted an entire day chasing my tail because the RFC contained incorrect test vectors.
#IETF #RFC #openSource #programming #totp #hotp
@quixoticgeek @beasts like @nitrokey or just basic #TOTP / #HOTP or #PGP-based #2FA?

#xsukax Secure #Authenticator

https://github.com/xsukax/xsukax-Secure-Authenticator

Demo: https://xsukax.github.io/xsukax-Secure-Authenticator/

A privacy-focused, #client-side #two-factor authentication (2FA) application that generates Time-based One-Time Passwords (TOTP) and #HMAC-based One-Time Passwords (HOTP) entirely within your browser. No server communication, no tracking, complete control over your authentication codes.

#totp #hotp

@sushimcpe I guess #Microsoft does bespoke things (like #Fortinet) instead of existing Standards like #TOTP & #HOTP

  • Or does it spit out standard #2FA codes like 918273 ?

Given that there are more attacks than yesterday, I presume that my personal research is successful. 😋

Last week I started wondering whether #HOTP #MFA (and by extension TOTP) are #zeroknowledge #zeroknowledgeproof. I couldn't find an immediate answer, but even more, there were very few results combining these two topics. So I did my own research and evaluation.

https://dannyvanheumen.nl/post/analysis-are-hotp-zero-knowledge-proofs/

https://mastodon.social/@cobratbq/115302085011196483

Analysis: are HOTP-based one-time passwords zero-knowledge proofs? · Timelessness

I have posted the initial version for the analysis on 'are #HOTP #zeroknowledge proofs'.
Although the blog post is not very mathematical in nature, I seem to have covered all relevant aspects. Previous social media posts covered the gist, but there is more detail present in the blog post.

https://dannyvanheumen.nl/post/analysis-are-hotp-zero-knowledge-proofs/

#zeroknowledgeproof #security #computerscience #MFA

Analysis: are HOTP-based one-time passwords zero-knowledge proofs? · Timelessness

Intuitive explanation for #zeroknowledge #zeroknowledgeproof analysis for #HOTP #MFA principle.

#security #analysis

@sleepybisexual also anything but #TOTP & #HOTP is just garbage.

  • Personally, I think the only good #2FA is #PGP-based but very few sites support it.

@dalias nodds in agreement...

I can see why they want to push for #2FA and have #business customers mandate that for accounts cuz "#CheckboxSecurity" and stuff...

  • But even then corporate security and supply chain security should not rely on those solely...

Worst when #2FA doesn't allow #privacy-friendly options like TANs and/or #TOTP / #HOTP but demand #PII like a #PhoneNumber!

  • Mandating #eMail and using that for 2FA is also a shit idea...

@ohno_itsnate @GrapheneOS I recommend looking at #TOTP & #HOTP for #2FA.

As for devices, I can vouch for @nitrokey !