Hacker News new | past | comments | ask | show | jobs | submit login

What about the ways this could improve security, such as by really making hardware 2fa easy to do online?



Find another way to access that kind of security hardware. That's the kind of thing that should be mediated through a strictly limited API in the browser anyway, where standardized UI can be provided.


Many people have been using two factor authentication for some web pages through SSL, PKCS11 modules and client side certificates on USB cryptokeys or smartcards for ages.

I always find it funny how each new browser and OS release makes it a little more hidden and a bit more convoluted to set it up. All while more and more web developers complain what a big problem secure authentication on the web is.


That is probably one of the driving forces behind this and similar technologies (NFC and Bluetooth LTE integration with the browser). All technologies supported by 2FA standard Fido U2F incidentally.

So yeah, I understand why adding this to a web browser seems unwanted, but as long as the API is well-defined and built with security as its first and primary concern, this could actually improve the overall security of on-line services significantly by making two-factor authentication something your browser just does, and does right. I can recommend skimming the Fido U2F spec [1] to anyone with doubts about the applicability and necessity of this standard.

The linked article basically starts with a section on privacy and security concerns though, so that is somewhat reassuring.

1: https://fidoalliance.org/specifications/overview/ (look for U2F in particular)


All you really need for that is a smartcard and a (USB) card reader to plug it into. Those could be integrated into one USB device also. That is an existing technology which is already deployed and in widespread use.


I'm unsure if Smartcards classify as NFC, but there's also WebNFC.

https://w3c.github.io/web-nfc/


Yubikey NEO?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: