21 Sep 2016

alexei gives demo on u2f@github, shows various makes of hw keys and explains the communication methods different ones support (usb, nfc, bt)

rob demonstrates ms windows built in features for pin or facial recognition

authenticator from phone to windows via bt

webauthn meant to provide a uniform api to be able to speak to this multitude of different types of devices

alexei shows yubikey registration on dropbox, mentions how this is usable by public sites and enteprises

i think search was on u2f key (to be non-manufacturer specific)

aaron shows indieauth which is a service to abstract out and permit user to choose oauth or other services the user prefers

eg using github, fb, twitter or other service

federated login but not choosing one explicitly as many sites do "log in with facebook"

liam points out two problems - loosing key and someone finding/stealing and then using key

alexei responds that use case is exactly why they recommend using these keys as a second and not sole factor

how do you support users that have lost or break their key?

suggestion is that people keep a spare and have both registered (enteprise example but applicable to websites)

alexei shows comparison of otp vs hw key usability and user efficiency

also support is lower cost for hw key over time. both have initial learning curve but key is lower there too

discussion of ensuring user is identified properly when registering key[s]

lisa explains accessibility especially learning and cognitive disabilities concerns

not needing to remember a password is good, having something you can loose or forget how to use is bad

also please be sure you streamline so they only need to log in once, not repeatedly

think about usability in registration process

vivien think of supporting your mom scenario (we have all been there)

(dad too)

talking a non-technical person through the process including purchasing key

affordability is also a concern, $50 is a big expense for some. requiring people to pay for better security will result in those with less financial means losing

shipping pre-registered and training videos help

alastairc wonders why we are still keeping username+password as a factor

complimenting gpg indieauth example

Vijay (from ms) that is why we are looking for a single way (webauthn) to represent various forms of auth such as facial recognition

goal is to go away from passwords entirely and replace that auth mechanism as well

best 2fa model imho is not just 2 methods but: something you know, and something you have

know could be gpg passphrase

wendy likes unlinkable authentication (that doesn't reveal identity)

