Re: Interest in a push-based two-factor auth standard?

Alex Jordan <alex@strugee.net> Tue, 07 March 2017 20:37 UTC

Return-Path: <alex@strugee.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 84AB5129577 for <ietf@ietfa.amsl.com>; Tue, 7 Mar 2017 12:37:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.903
X-Spam-Level:
X-Spam-Status: No, score=-1.903 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CPo5P_44nryc for <ietf@ietfa.amsl.com>; Tue, 7 Mar 2017 12:37:25 -0800 (PST)
Received: from steevie.strugee.net (strugee.net [216.160.72.225]) by ietfa.amsl.com (Postfix) with ESMTP id 7493A129540 for <ietf@ietf.org>; Tue, 7 Mar 2017 12:37:25 -0800 (PST)
Received: from localhost (unknown [207.251.103.46]) by steevie.strugee.net (Postfix) with ESMTPSA id A42E276E369; Tue, 7 Mar 2017 12:37:23 -0800 (PST)
Date: Tue, 07 Mar 2017 15:37:19 -0500
From: Alex Jordan <alex@strugee.net>
To: Phillip Hallam-Baker <phill@hallambaker.com>
Subject: Re: Interest in a push-based two-factor auth standard?
Message-ID: <20170307203719.GB6276@Alexs-MacBook-Pro>
References: <20170302055128.GJ12470@Alexs-MacBook-Pro> <CAMm+Lwg_kAtYUGivYSF5ZzF5nfywS4rzYG88UEzxgjRL2_=83Q@mail.gmail.com>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="FkmkrVfFsRoUs1wW"
Content-Disposition: inline
In-Reply-To: <CAMm+Lwg_kAtYUGivYSF5ZzF5nfywS4rzYG88UEzxgjRL2_=83Q@mail.gmail.com>
User-Agent: Mutt/1.7.2 (2016-11-26)
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/QojLXlqlhIaXu5TlSoXyPiUpTUc>
Cc: IETF Discussion Mailing List <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 07 Mar 2017 20:37:26 -0000

On Mon, Mar 06, 2017 at 08:05:11AM -0500, Phillip Hallam-Baker wrote:

> What we are discussing goes beyond two factor auth. If you have a cell
> phone with a device specific signature key, it can sign the response which
> means that you automatically collect up a non repudiable audit log of the
> user's actions. This is beyond anything possible with OTP number sequences
> or USB dongles.

Indeed. I suspect there are a lot of unexplored uses for such a
standard, but haven't explored it fully yet. (Note also that the lack
of deniability could be seen as a positive thing _or_ a negative
thing, depending.)

> ​i am interested and have developed several protocols of this type using
> JSON. My work provides prior art back to 2010 at the very least.

Are there any public references for this work?

I think what makes most sense at this point is for me to draw up a
rough Internet draft and then send it to the Security area and see
what they think the best way forward is. Looking at prior work will
probably aid in the design of such a draft.

Does that seem okay to those who have expressed interest in this?

Cheers!

AJ