Is FIDO the future instrument to prove our identity?

Discussion in 'privacy technology' started by Minimalist, Oct 18, 2018.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://blog.malwarebytes.com/security-world/2018/10/fido-future-instrument-prove-identity/
     
  2. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,402
    Nice but basic read. I use FIDO and FIDO2 many times a day. Best thing going, but many site owners are just too damn lazy to set it up.
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  4. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,402
    I use U2F-FIDO as a requirement to access my accounts from the devices you listed. While the devices themselves in some cases can be controlled I don't actually have that need. Personal applications would be facebook, gmail, dropbox, password manager, etc.... I don't need U2F for my linux laptop because you aren't getting in pre-boot, period!
     
  5. deBoetie

    deBoetie Registered Member

    Joined:
    Aug 7, 2013
    Posts:
    1,832
    Location:
    UK
    Fido is a suite of things. The U2F fob concept is excellent, but Fido also supports biometric identities which I am unfond of.

    I think it's important to separate authentication from identification.

    Of course, the reason many sites have not adopted it is mainly because it is reasonable at privacy protection - all it knows is a site specific secret which is encoded in the fob. But the sites want to share you and your interests with other parties, hence want to correlate your identity.

    The other issue is historically the lack of quality browser support, but FF should support it properly now (as well as Chrome), though I haven't tested recently.
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I basically want devices themselves to act as the second factor of authentication. In case you're using someone else device, then you do need a smartphone or USB Key. Can't believe that this stuff hasn't gone mainstream yet.

    https://www.intel.com/content/www/us/en/security/online-connect.html
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.