Everything You Want to Know About WebAuthn

Поділитися
Вставка
  • Опубліковано 6 жов 2024

КОМЕНТАРІ • 24

  • @LeonardPham
    @LeonardPham 5 місяців тому

    This was one of the better overviews of WebAuthN that I've watched. It's aged well, considering it was recorded three years ago. Thank. you!

  • @LonliLokli
    @LonliLokli 2 роки тому +6

    A lot of concerns actually, eg how to verify user when he logins from computer while his key is stored on mobile?

    • @OddWoz
      @OddWoz Рік тому +1

      The way I understand it is you would register/authorize each device or otherwise share keys between them. I favor YubiKeys and the “roaming” approach.

  • @pging8328
    @pging8328 2 роки тому +3

    The real hurdle to adoption is getting software developers to implement this (instead of some off the rack solution like devise), and even more tricky, is getting management to "OK" developers spending "forever" to implement such an authentication solution.

  • @susmitt
    @susmitt 3 роки тому +3

    Very high quality presentation . Thanks !!

  • @youmal30
    @youmal30 Рік тому +1

    That was a great introduction. Well done.

  • @lorimaydeguzman1110
    @lorimaydeguzman1110 3 роки тому +2

    The script returned "No PA found" in my browser when I tried it. May I know what should I do to allow support on PA? Thanks a lot!! And great presentation by the way!! :)

  • @ryanjohnson4566
    @ryanjohnson4566 2 роки тому +1

    Attestation Type & Authenticator Type will just confuse our end users for sure in the form at 6:46. Would there be a more user friendly way to register?

  • @vmobile890
    @vmobile890 2 роки тому +2

    Face fingerprint and key chain key easier to steel than password by theft or when knocked down or dead .

    • @whydiswhydat
      @whydiswhydat Рік тому

      someone has to ripp your face or finger off even if they steal it.

    • @OddWoz
      @OddWoz Рік тому +1

      Actual physical access is required, which means it usually has to be a physical/targeted attack to impact you. Not much out there to defend against the $5 wrench, and passwords are just as highly vulnerable in that situation.
      That’s why a _combination_ of things you are(biometrics), things you know(passwords), and things you have(physical keys) are the most advisable method. At least with physical keys invoked you are far less likely to be infiltrated by credentials being leaked or exfiltrated from a database. Public keys are far less useful without the private key to sign with. Passwords alone are not at all superior.

  • @TheLoGgIDK
    @TheLoGgIDK 2 роки тому +1

    Just the explanation I was missing

  • @samuelbie2122
    @samuelbie2122 2 роки тому +2

    What happens for example if i lose the divice i registered with. This means that i can just loggin from the divice i registered with?

    • @OddWoz
      @OddWoz Рік тому +1

      I use YubiKeys and, for example, with my spares I have to register each one individually that way they both/all can work equally in case of loss. I presume that’s exactly how it works for mobiles as well. If you do not register a spare/multiple devices, share keys with another device somehow, or use a cloud service(like Authy, not recommended) that will share the keys amongst devices for you…. Then yes, you would effectively be locked out of the service/account unless they offered backup codes when setting it up or provide an account retrieval process (which can also be a glaring vulnerability depending on how it’s implemented).

  • @jeroen5654
    @jeroen5654 2 роки тому +2

    Great presentation! One question though: if the computer does not have a finger/face sensor and the user hasn't got a key, what's the fallback scenario of WebauthN? Can anyone without a finger/face sensor use there windows/mac password instead? And can users use this even if their administrators disabled stuff like installing apps for example?

    • @whydiswhydat
      @whydiswhydat Рік тому

      this technology is for the future, not the past. most of the laptops, and phones will have biometrics.

  • @bhumijgupta
    @bhumijgupta 2 роки тому

    This is a very helpful and informative. Thanks!

  • @solifassalimu1941
    @solifassalimu1941 2 роки тому

    insightful overview!

  • @tyrone9334
    @tyrone9334 2 роки тому

    Great video. Thanks!

  • @lagz89
    @lagz89 3 роки тому

    Great talk, fluid speaking.

  • @Unyk-life
    @Unyk-life 3 роки тому

    good intro!

  • @RogerYeahmon
    @RogerYeahmon 4 дні тому

    "kelly robinson".. quintessential English name..

  • @raphaelcharlie7199
    @raphaelcharlie7199 2 роки тому

    Your voice is beautiful, use it more