this post was submitted on 10 Apr 2022
15 points (100.0% liked)
Security
5014 readers
8 users here now
Confidentiality Integrity Availability
founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
SQRL is solving lot's of these problems without needing to keep state (there is no per-site state) in sync: https://sqrl.grc.com/pages/what_is_sqrl/
This seems like it requires websites to allow using sqrl identities. Is that correct?
yes, they have to keep 2 more tokens (or so) and add support
I can't find any technical information on that site. Just reading it makes it sound basically like an SSO solution except the third party is software you run or some cryptography instead of a third party. However I would like to read the technical details.
No, it does not require a login portal or so. All you need to do is to support it on the website and it requires client side software (e.g. Android application) but that does not require any data sync after it is set up. It does not replace SSO, just the use of password to log in.