Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Malware on the phone isn't covered by their attacks and weaknesses page. (https://www.grc.com/sqrl/attacks.htm)

The Userview page seems to miss that point as well: (https://www.grc.com/sqrl/userview.htm)

> In other words, only the smartphone's owner can use the system to assert their identity, and nothing will prevent them from asserting their identity whenever they wish to.

I think they mean "only the person currently in possession of the smartphone" ...

except they go on to say that whoever has the phone has to identify themselves to the phone using a strong password.

> The SQRL system was specifically designed to eliminate username and password authentication to remote websites. But controlling access to SQRL authentication itself requires the smartphone's owner to prove their identity to their own phone.

> And to that end, “a secret only the user knows” is still the best technique for users to repeatedly, quickly, easily and privately prove their identity to their own smartphone.

> The cryptographic design of the SQRL system inherently provides identification security for every website it contacts. In that sense the system itself is fully secure without any password protection. We refer to the SQRL password as a “local password” because it is only used to prevent others from using the SQRL smartphone app to impersonate its owner.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: