Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PasswordLess Authentication (in association with FIDO Alliance) #1353

Closed
aka-0x4C3DD opened this issue Jun 10, 2022 · 5 comments
Closed

PasswordLess Authentication (in association with FIDO Alliance) #1353

aka-0x4C3DD opened this issue Jun 10, 2022 · 5 comments
Labels

Comments

@aka-0x4C3DD
Copy link
Contributor

Is your feature request related to a problem? Please describe.
Passworless is the future. FAAMG Companies have already boarded the trend. But the catch is all of yhose will be closed source.

Describe the solution you'd like
An Open-Source Solution, with Fido Alliance Standardization for PasswordLess Logins.

Describe alternatives you've considered
If not here, I have to go look for other competetors with Open-Source Password Management and PasswordLess Authentication offerings.

Additional context
Big Companies have already started boarding the Passwordless Authentication trend. We need have some Open-Source Solutions too so that the newer technologies can be more reliable by public and adoption rate can be higher.

@J-Jamet
Copy link
Member

J-Jamet commented Jun 10, 2022

FAAMG Companies have already boarded the trend

I already want to put things in context, I am just an independent. I work on my free time on subjects that I am passionate about and that are related to my values.

An Open-Source Solution, with Fido Alliance Standardization for PasswordLess Logins.

With what technology specifically, your sentence is too vague. Authentication with Fido2 secret is under study, you can of course contribute to the functionality or propose another viable one.

If not here, I have to go look for other competetors with Open-Source Password Management and PasswordLess Authentication offerings.

I think you don't understand the concept of open source very well, the goal is the sharing of information. If another open source solution offers a viable solution in line with the technology and philosophy of the application, it will be integrated. But maybe your idea is to invest, in that case be more precise.

Big Companies have already started boarding the Passwordless Authentication trend. We need have some Open-Source Solutions too so that the newer technologies can be more reliable by public and adoption rate can be higher.

What would be your concrete proposal ?

@aka-0x4C3DD
Copy link
Contributor Author

I already want to put things in context, I am just an independent. I work on my free time on subjects that I am passionate about and that are related to my values.

I am dearly sorry for my words. I wasn't aware of that.

I think you don't understand the concept of open source very well, the goal is the sharing of information. If another open source solution offers a viable solution in line with the technology and philosophy of the application, it will be integrated. But maybe your idea is to invest, in that case be more precise.

Thanks for explaining me the Open-Source concept better. I actually have seen a lot of Open sourced apps that doesn't provide features or aren't that properly implemented as their competitors, which are also open source, which is why I wrote the statement. It maybe my personal feeling, and not an overall case whatsoever.

What would be your concrete proposal ?

KeePass DX Virtual Security Key is my concrete proposal. I saw Big MNC's working with FIDO Alliance to make things like iCloud Passkey is in the works. I want something like that, platform independent, that can be more or less blindly trusted by all. Yes, it's an Idea, worth investing I feel, seeing the standardization of client authentication protocols by big companies. If / Whenever possible, please work on it.

P.S.: IDK if it's OK to say these here, but still saying, Great App, Bro. IDK what you do for a living, but I wish you to prosper in your field. Good Luck!

@J-Jamet
Copy link
Member

J-Jamet commented Jun 11, 2022

I actually have seen a lot of Open sourced apps that doesn't provide features or aren't that properly implemented as their competitors

You have to put yourself in the context of the creators, if they are people who have moved on, the code can at least be taken over. I see that competition is something you like a lot but it's more related to helping and sharing, at the beginning often just because it's fun and to learn things, not to competition...
Nothing prevents you from creating the product that fits your needs.

KeePass DX Virtual Security Key is my concrete proposal

It's not a concrete proposal, it's a cool commercial name.

I want something like that, platform independent, that can be more or less blindly trusted by all. Yes, it's an Idea, worth investing I feel, seeing the standardization of client authentication protocols by big companies. If / Whenever possible, please work on it.

Okay, but what is your value proposition? skill, investment, any help? I want a lot of things too.

To summarize: Your concrete proposal is to ask guys who work on their own time to compete with a new multinational technology whose code is closed and requires centralization connection servers, providing global standardization and the adoption must be made by everyone.
It's nice that you said thank you, but I'm not a wish-fulfilling genie. :D
At least, concrete technical proposals with implementation discussions are needed.

P.S.: IDK if it's OK to say these here, but still saying, Great App, Bro. IDK what you do for a living, but I wish you to prosper in your field. Good Luck!

Thanks. Spoiler alert, I am a developer.

@aka-0x4C3DD aka-0x4C3DD closed this as not planned Won't fix, can't repro, duplicate, stale Jun 11, 2022
@aka-0x4C3DD
Copy link
Contributor Author

Hey buddy,
Sorry to disturb. My account was being used by one of my friend to convey his thoughts on PasswordLess Auth. Probably, he wasnt aware of this this thing existing as FIDO2 from a long time and also is on works as HMAC-Secret FIDO2 in this platfrom as you have mentioned earlier. We were attending all the Google & Apple Developers Conference, and he got inspired from that and wrote this to you, lacking technical knowledge I afaik, for which it seems he got scoffed a bit too.
Anyways, sorry for the time wasted. Happy Developing! ;)

@alensiljak
Copy link

Not sure if this feature is being tracked elsewhere. Here's Bitwarden's implementation: https://bitwarden.com/blog/passwordless-authentication-access-your-bitwarden-web-vault-without-a-password/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants