home.social

#hotp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hotp, aggregated by home.social.

  1. I'm looking for a good overview/comparison of different #MFA/#2FA or #PasswordLess authentication protocols.

    The recent #Fido2 #MitM risk made me aware that I need to learn more.

    Pointers and #BoostWelcome

    #fedipower #wisdomOfTheCrowd #FollowerPower

    As the best way to get an answer on the internet, is to state something wrong, let's try this 😜

    #FIDO and FIDO2 are actually a whole set of (related?) protocols.
    FIDO includes FIDO #UAF (Universal Authentication Framework) and FIDO #U2F (Universal Second Factor).

    FIDO2 is the "successor" of FIDO and consists of two parts.
    #WebAuthn and #CTAP (Client to Authenticator Protocol). From the name I would guess that WebAuthn is for web stuff (requiring browser support) and CTAP is for IT infrastructure stuff (???)

    #Passkey is based on #Fido2
    Other related concepts or protocols are #OTP (one-time passwords), #TOTP (Time-based One-time Password) and #HOTP (“H” in HOTP stands for Hash-based Message Authentication Code (HMAC))

    Not sure how #SmartCards play into this.

    And not sure which of these methods would work for an offline authentication login into your laptop (and ideally also as key for whole disk encryption)

  2. I'm looking for a good overview/comparison of different #MFA/#2FA or #PasswordLess authentication protocols.

    The recent #Fido2 #MitM risk made me aware that I need to learn more.

    Pointers and #BoostWelcome

    #fedipower #wisdomOfTheCrowd #FollowerPower

    As the best way to get an answer on the internet, is to state something wrong, let's try this 😜

    #FIDO and FIDO2 are actually a whole set of (related?) protocols.
    FIDO includes FIDO #UAF (Universal Authentication Framework) and FIDO #U2F (Universal Second Factor).

    FIDO2 is the "successor" of FIDO and consists of two parts.
    #WebAuthn and #CTAP (Client to Authenticator Protocol). From the name I would guess that WebAuthn is for web stuff (requiring browser support) and CTAP is for IT infrastructure stuff (???)

    #Passkey is based on #Fido2
    Other related concepts or protocols are #OTP (one-time passwords), #TOTP (Time-based One-time Password) and #HOTP (“H” in HOTP stands for Hash-based Message Authentication Code (HMAC))

    Not sure how #SmartCards play into this.

    And not sure which of these methods would work for an offline authentication login into your laptop (and ideally also as key for whole disk encryption)

  3. I'm looking for a good overview/comparison of different #MFA/#2FA or #PasswordLess authentication protocols.

    The recent #Fido2 #MitM risk made me aware that I need to learn more.

    Pointers and #BoostWelcome

    #fedipower #wisdomOfTheCrowd #FollowerPower

    As the best way to get an answer on the internet, is to state something wrong, let's try this 😜

    #FIDO and FIDO2 are actually a whole set of (related?) protocols.
    FIDO includes FIDO #UAF (Universal Authentication Framework) and FIDO #U2F (Universal Second Factor).

    FIDO2 is the "successor" of FIDO and consists of two parts.
    #WebAuthn and #CTAP (Client to Authenticator Protocol). From the name I would guess that WebAuthn is for web stuff (requiring browser support) and CTAP is for IT infrastructure stuff (???)

    #Passkey is based on #Fido2
    Other related concepts or protocols are #OTP (one-time passwords), #TOTP (Time-based One-time Password) and #HOTP (“H” in HOTP stands for Hash-based Message Authentication Code (HMAC))

    Not sure how #SmartCards play into this.

    And not sure which of these methods would work for an offline authentication login into your laptop (and ideally also as key for whole disk encryption)

  4. I'm looking for a good overview/comparison of different #MFA/#2FA or #PasswordLess authentication protocols.

    The recent #Fido2 #MitM risk made me aware that I need to learn more.

    Pointers and #BoostWelcome

    #fedipower #wisdomOfTheCrowd #FollowerPower

    As the best way to get an answer on the internet, is to state something wrong, let's try this 😜

    #FIDO and FIDO2 are actually a whole set of (related?) protocols.
    FIDO includes FIDO #UAF (Universal Authentication Framework) and FIDO #U2F (Universal Second Factor).

    FIDO2 is the "successor" of FIDO and consists of two parts.
    #WebAuthn and #CTAP (Client to Authenticator Protocol). From the name I would guess that WebAuthn is for web stuff (requiring browser support) and CTAP is for IT infrastructure stuff (???)

    #Passkey is based on #Fido2
    Other related concepts or protocols are #OTP (one-time passwords), #TOTP (Time-based One-time Password) and #HOTP (“H” in HOTP stands for Hash-based Message Authentication Code (HMAC))

    Not sure how #SmartCards play into this.

    And not sure which of these methods would work for an offline authentication login into your laptop (and ideally also as key for whole disk encryption)

  5. I'm looking for a good overview/comparison of different #MFA/#2FA or #PasswordLess authentication protocols.

    The recent #Fido2 #MitM risk made me aware that I need to learn more.

    Pointers and #BoostWelcome

    #fedipower #wisdomOfTheCrowd #FollowerPower

    As the best way to get an answer on the internet, is to state something wrong, let's try this 😜

    #FIDO and FIDO2 are actually a whole set of (related?) protocols.
    FIDO includes FIDO #UAF (Universal Authentication Framework) and FIDO #U2F (Universal Second Factor).

    FIDO2 is the "successor" of FIDO and consists of two parts.
    #WebAuthn and #CTAP (Client to Authenticator Protocol). From the name I would guess that WebAuthn is for web stuff (requiring browser support) and CTAP is for IT infrastructure stuff (???)

    #Passkey is based on #Fido2
    Other related concepts or protocols are #OTP (one-time passwords), #TOTP (Time-based One-time Password) and #HOTP (“H” in HOTP stands for Hash-based Message Authentication Code (HMAC))

    Not sure how #SmartCards play into this.

    And not sure which of these methods would work for an offline authentication login into your laptop (and ideally also as key for whole disk encryption)

  6. Authenticator app? What's that? I use the terminal 🔥

    🔒 **cotp**: Trustworthy and encrypted TOTP/HOTP authenticator with a TUI.

    🚀 Supports importing (e.g. from Aegis, Authy, Google Authenticator, etc.)

    🦀 Written in Rust & built with @ratatui_rs

    ⭐ GitHub: github.com/replydev/cotp

  7. #Shaarli: GitHub - beemdevelopment/Aegis: A free, secure and open source app for Android to manage your 2-step verification tokens. - Application mobile d'authentification double facteur (2FA).
    Permet d'importer les jetons depuis d'autres applications (accès root) et de sauvegarder automatiquement les jetons. : github.com/beemdevelopment/Aeg #totp #hotp #2fa

  8. Someone at GitHub asked for websites using HOTP.

    It’s true that all public sites use TOTP, I personally never registered to a site with 2FA based on HMAC. To me it’s probably used by enterprises.

    Do you know such sites or services?

  9. Jan <3 @rollbrettklauen ·

    Just looked at code I implemented a year ago and cringed. I mean I grew as a developer but why did I implement a state full version of and ?

  10. #OneTrickPony is a modern #Java library that implements support for One-Time Passwords. Built-In support is provided for the #HOTP (RFC 4226) and #TOTP (RFC 6238) algorithms. bit.ly/3YoVQ6M #Security

  11. heise+ | 2FA: Fünf kostenlose Authenticator-Apps für Android im Vergleich

    Alle von uns getesteten Authenticator-Apps können Einmalcodes generieren. Sie bieten allerdings unterschiedliche Einstellungsmöglichkeiten und Funktionen.
    2FA: Fünf kostenlose Authenticator-Apps für Android im Vergleich
  12. @Troll Solution : #HOTP (RFC 4226), au lieu de #TOTP. (Mais il a d'autres inconvénients, la vie n'est pas facile, ma bonne dame.)

  13. heise+ | Passwortmanager Keepass: So generieren Sie Einmalpasswörter

    Keepass kann Codes für die Zwei-Faktor-Authentifizierung generieren – oder die eigene Passwort-Datenbank damit schützen. So wird Keepass zur Passwort-Zentrale.
    Passwortmanager Keepass: So generieren Sie Einmalpasswörter
  14. #andOTP is a Free open source Two-factor authentication app for #Android - github.com/andOTP/andOTP Among its useful features are plain text or encrypted automated #backup, visual icons, QR-code scanning, minimal permissions, Android-keystore authentication and ability to import from most other #2FA apps.
    #backup #otp #totp #hotp #degoogle
    via magicfab.ca/liens/

  15. Prisa kodgudarna, tvåfaktorsautentisering på datamaskinen är här! #OTPClient ser ut att vara ett riktigt trevligt program med stark kryptering och lösenordsskydd för #2FA direkt på datorn. Men kanske för bekvämt i relation till ökad säkerhet med att ha 2FA på annan device? github.com/paolostivanin/OTPCl Tänk om #Sverige hade vettig öppen #eID där det räckte med tvåfaktor på dator eller mobil för identifiering oavsett system. #BankID #FrejaEID #TOTP #HOTP #WebAuthN