User Tools

Site Tools


login

If you want to send us your comments, please do so. Thanks
More on comments


Login

Login to local servers

ServerLoginRemark
Cupshttp://localhost:631
Webminhttps://192.168.1.100:10000/Or use localhost or 127.0.0.1

SRQL

A better login system compared to Passkeys
The SQRL home page
Advantages:

  • A third party server is not needed. This is better for privacy and security
  • Phising proof

Passkeys

Passkeys are public key credentials synced via the iCloud, Microsoft, Google or other account of the user and protected by the Face ID, Touch ID, Windows Hello, device PIN or device gesture of the user

Better alternative

Phising risks

Disadvantages:

  • Needs a smartphone which costs money and has privacy issues
  • Needs a third party online service, server, to register the public key
    • That is a privacy issue. This service must be trusted. It can track where one logs in, when one logs in and the location via the IP-address and maybe more
  • Not phising proof. The authentication responsibility is outsourced to a 3rd party provider
    • Rather than doing the work of upgrading their own servers to become a first-party passkeys provider, a company can outsource their authentication responsibility to a 3rd party provider like OwnID. But in doing so, by punting in this way, they've bypassed passkeys phishing protections. This gives their visitors the false belief that they're getting the hack-proof benefits of passkeys without actually having them. This could be transient. But OwnID will presumably be selling their “instant onboarding” services and most websites will simply want easy logon without really caring about their visitor’s security. Source
  • Bluetooth has to be turned on on a mobile device in order to initiate passkeys. On an Android device that means de GPS is also turned on. So the application can harvest the location of the owner and send it home
  • The passkey functionality build into the operating system like Windows 11 can conflict with the passkey functionality build into the webbrowser
  • There is always the alternative option to still login with a username and password. So why are passkeys needed?
  • Passkeys are not transportable to an other device
  • The device lock mechanism needs to be active via biometric, pin or other login credentials. If one uses a device without any of these passkeys can not work
  • From: Unixsheikh with title: “Are passkeys really the beginning of the end of passwords? I certainly hope not.”:
    • My password is mine. I control my password. I own my password. I am not dependent upon some third party closed proprietary operating system or device to handle my security.
    • The Passkey concept pushes data ownership one step closer to the Big Tech industry.
    • Biometric-based authentication factors are favoured.
  • There is the risk of “vendor lock-in”: becoming dependent on a specific service provider or technology. For example, using passkeys built into a particular operating system or device. Like with Google and Apple

E-mail address

Since many if not all websites have the ability to reset the password that means that the e-mail provider, say Google or Microsoft, or a hosting provider where someone hosts their e-mail account, have full access to all websites where that e-mail address is provided as part of the login credentials (usually e-mail address and password).

So without OPT or some other 2FA authentication method, you can never be sure what happens to your account.

On the other hand, to log in, the password has to be reset. So if you can't get logged in then the above might be a cause. Then request a log of IP addresses from which was logged in so you can be sure it wasn't you yourself.

The fact that the password has to be reset and that you notice this the moment you want to log in makes it not as unsecure as it seems at first glance because it gets noticed and if it happens more often the suspected will come to light. It does put a sizeable responsibility on the hosting companies. If they leak then the account is probably comprimized

The e-mail account is a single point of failure


Main subjects on this wiki: Linux, Debian, HTML, Microcontrollers, Privacy

RSS
Disclaimer
Privacy statement
Bugs statement
Cookies
Copyright © : 2014 - 2024 Webevaluation.nl and the authors
Changes reserved.

This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.More information about cookies
login.txt · Last modified: 26-02-2024 19:07 by wim