Re: [homenet] webauthn for routers

Michael Thomas <mike@fresheez.com> Thu, 13 June 2019 20:22 UTC

Return-Path: <mike@fresheez.com>
X-Original-To: homenet@ietfa.amsl.com
Delivered-To: homenet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4DA1612074E for <homenet@ietfa.amsl.com>; Thu, 13 Jun 2019 13:22:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=fresheez.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fITJRVfbrFSH for <homenet@ietfa.amsl.com>; Thu, 13 Jun 2019 13:22:03 -0700 (PDT)
Received: from mail-pl1-x62f.google.com (mail-pl1-x62f.google.com [IPv6:2607:f8b0:4864:20::62f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9E66A1206AE for <homenet@ietf.org>; Thu, 13 Jun 2019 13:22:03 -0700 (PDT)
Received: by mail-pl1-x62f.google.com with SMTP id cl9so2702plb.10 for <homenet@ietf.org>; Thu, 13 Jun 2019 13:22:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fresheez.com; s=fluffulence; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-language; bh=pkODHPJ545qyODiT/PaH7fDS5/pUJ3VPzaCPCAV7zrI=; b=BatTdsvrRjrSwImrA8NhoqWOM2ZoU0rbpp0cY1VTaN1xxsYJnecMHX+U4kNJVmI7OJ XSwn9LOxX8kcSsZzkuyHVrFA4y/aFA/0rerFg84HaM3KCvA39Gt6f1/tCgR6RLnEoEUC 9sJAHMViRwuVyan10xV9WqAHG/FdkCA2T8StE=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language; bh=pkODHPJ545qyODiT/PaH7fDS5/pUJ3VPzaCPCAV7zrI=; b=UOFgiZyLGYL2YPfN4KgHZrSORMWAma27HAIRNH4llx0hX10HpPPEW9LQV+IPUnjWFD 2C0M+DW7R+0bQBu0CSY/opN1efZj5D+BEzy70oGxi2OHRnJ2II6Mydbk7CbZpPLZ68nk /pdrT6RVhbc8T+XIeboPI7Afnd1CLVtHa60MJsCvgndoAJg9T7xCVAbHmiNYWtF4UG/6 SES46jWiYD2C2e3wZcXRSbevOX3Yn+oL0HbsIgo0A5kCfRelnlaX6j8B0LzWfwbHqyiA qWg/vkR/djKSl1zEAJDlDN84Prv0eKJM12iz1tL062ICPlLhg58XapQtG9PWAsaQaJt3 e+xw==
X-Gm-Message-State: APjAAAX//kSa2pS51QaVWJULuiKfNTysF2qpPMCmneR3k1bLYLVPaAj6 3qvQNSrd5I034DotCqWHGui+fK8z4FM=
X-Google-Smtp-Source: APXvYqzCwBsnwULjTNzFgEMJqv+Rv4cyOJsv2UHp1iB2Uf7QM0yDQnsbAADns/a2mj6sIbtbayYGAg==
X-Received: by 2002:a17:902:b110:: with SMTP id q16mr82349700plr.218.1560457322705; Thu, 13 Jun 2019 13:22:02 -0700 (PDT)
Received: from Michaels-MacBook.local (107-182-42-248.volcanocom.com. [107.182.42.248]) by smtp.gmail.com with ESMTPSA id l63sm498692pfl.181.2019.06.13.13.22.00 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 13 Jun 2019 13:22:01 -0700 (PDT)
To: Ted Lemon <mellon@fugue.com>
Cc: Michael Richardson <mcr@sandelman.ca>, homenet@ietf.org
References: <CADZyTkkgd8f49V+yoZvPZXx3b-_YRzpgUY1-obroq9QMLnFWNw@mail.gmail.com> <6179.1560377924@localhost> <604b4062-f2c5-30af-73ff-2e97b7541a9b@fresheez.com> <30470.1560435490@localhost> <cde3329b-cc06-b4eb-5d87-cf74f21368ea@fresheez.com> <496DBED4-24E6-49FE-B9D3-C2BFC7ACEE98@fugue.com> <20d72a3f-0b8f-c958-2482-25358854a96e@fresheez.com> <384451EC-7938-48B6-B167-1C246385C6D7@fugue.com> <fc40f26f-0dc3-91bb-03a0-7e7d8820e931@fresheez.com> <3461D44E-DD00-485D-B1CB-2F5356653403@fugue.com> <4167255a-9766-d155-cafa-44a27bec9a45@fresheez.com> <6B0BD10A-52A8-4DA6-82E2-BE4196041EE4@fugue.com> <d633bcce-cd61-6e86-ae7c-0aa26c7ed815@fresheez.com> <306AAFBA-39D0-489A-8698-F31A6C4BEC78@fugue.com> <8d490410-8ca4-0d74-488e-5c632f8a00b8@fresheez.com> <C3C5279A-14F6-42D2-B436-F2FD88CACC66@fugue.com> <3090e039-30d8-5304-d208-a009504acc58@fresheez.com> <1F477030-124B-4BB7-8023-94017EF5648B@fugue.com> <11f639ce-2853-4d7b-34c1-7dbef754944f@fresheez.com> <4C7ACB85-BA25-49CC-89BF-3B14E11E5F88@fugue.com>
From: Michael Thomas <mike@fresheez.com>
Message-ID: <b9a11c0f-1488-6dc2-5463-9abb92da4d4b@fresheez.com>
Date: Thu, 13 Jun 2019 13:21:59 -0700
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:60.0) Gecko/20100101 Thunderbird/60.7.0
MIME-Version: 1.0
In-Reply-To: <4C7ACB85-BA25-49CC-89BF-3B14E11E5F88@fugue.com>
Content-Type: multipart/alternative; boundary="------------7E08D8161AB4CA1176EEB130"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/homenet/qnc3ToPA-D-xlMJL9jdg6Q3TPC0>
Subject: Re: [homenet] webauthn for routers
X-BeenThere: homenet@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF Homenet WG mailing list <homenet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/homenet>, <mailto:homenet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/homenet/>
List-Post: <mailto:homenet@ietf.org>
List-Help: <mailto:homenet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/homenet>, <mailto:homenet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Jun 2019 20:22:05 -0000

On 6/13/19 1:16 PM, Ted Lemon wrote:
> On Jun 13, 2019, at 4:08 PM, Michael Thomas <mike@fresheez.com 
> <mailto:mike@fresheez.com>> wrote:
>>
>> It would be good to do this on openwrt, that's for sure. I've never 
>> tried to hack on it, but it can't be too horrible.
>>
>>
> It’s dead easy if you have a Linux VM.   Just build a package, and 
> have a place it can be downloaded from.   When you make changes, 
> update the package.   You can debug using gdbserver. Let me know if 
> you need help with this.
>
>
Oh, ok. This is a lot easier because it doesn't care how many real 
interfaces you have, etc. You just need to modify the backend web login, 
and insert some js into the login page which can probably been snarfed 
off the net easily enough now.

Mike