I wish authentication on the web worked like this:

- Every browser has one (or more) public key(s).
- The browser presents the public key to the server on request.
- A public key can be shared between browsers of the same user.
- To give your friend access to a web site, you simply ask for their public key.

I know there are passkeys and TLS client certificates, but all implementations are majorly flawed and half-assed in my opinion.

#Web #Browser #WebAuth #Passkeys #Security #InfoSec #TLS

https://github.com/stupidwebauthn/server#flows

Building an authentication server for passwordless authentication NO PASSWORDS INCLUDED!!!

Registration: Sends email for account creation, then requests a passkey

Login: Client asks first for an email, then lists connected passkeys to login with

Work in progress... please let me know what you think

#passkey #webauth #passwordless

GitHub - stupidwebauthn/server

Contribute to stupidwebauthn/server development by creating an account on GitHub.

GitHub
Ayrıca #SAML tabanlı ağ kimlik doğrulaması için #WebAuth desteği, Geliştirilmiş Açık (OWE) Wi-Fi güvenlik desteği, KDE uygulamalarında sorunsuz kaydırmayı devre dışı bırakmak için yeni bir seçenek, Pil widget'ının simgesi için bir güç profili rozeti ve monitörünüze yerleşik renk profili verilerini kullanmak için yeni bir seçenek vaat ediyor.

"django-allauth 64.0.0 released"

https://allauth.org/news/2024/07/django-allauth-64.0.0-released/

* Added support for WebAuthn based security keys and passkey login.

#python #django #webauth #passkeys

django-allauth 64.0.0 released | allauth

"So do yourself a favour. Get something like bitwarden or if you like self hosting get vaultwarden. Let it generate your passwords and manage them. If you really want passkeys, put them in a password manager you control. But don't use a platform controlled passkey store, and be very careful with security keys."

https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

Sad to read this.

#passkeys #webauth #authentication #passwordmanagers

Passkeys: A Shattered Dream

Firstyear's blog

Passkeys - Threat modeling and implementation considerations | SlashID Blog

In this blog post, we review the current state of the technology from a security standpoint and we’ll discuss some critical aspects of passkey implementation.

I'm making a TV-guide app for anime, in the open for all to experience and learn from!

Back to square one with #WebAuth, this time with client authentication! Time to dive into the spec, get confused, try something out, read the spec again, tear it all down… a virtuous cycle of understanding 😅

#Jiiiii #DevStream #tvOS #visionOS #macOS #Anime #Swift #SwiftUI #Vapor #BuildInPublic

Come chill with me: https://youtube.com/live/4r_8YXxI4rw

Bevor Sie zu YouTube weitergehen

@Foxboron
Here in the US, you can get several models for $15-25, a few even less.
Not free but not expensive.
#fido #webauth

@bitwarden has finally started to push out #passkey support.
I have waited so long for this and I am really happy to see it!
https://www.theverge.com/2023/11/2/23943173/bitwarden-passkey-support-released-browser-extension

#fido2 #webauth #infosec #cybersecurity #mfaboston

Bitwarden begins adding passkey support to its password manager

Bitwarden is adding support for passkeys in the latest version of its browser extension. But it’s not currently possible to store them in its mobile app.

The Verge
Let us spread the #Joomla #cms power. Everybody can post a feature once a day . I start with #Multifactorauthentification #webauth #webdev