FIDO UAF
From MgmtWiki
Full Title or Meme
Universal Authentication Framework provides a guide for Fast ID Online (FIDO).
Content
The following is from the FIDO docs.
The UAF protocol allows online services to offer password-less and multi-factor security. The user registers their device to the online service by selecting a local authentication mechanism such as swiping a finger, looking at the camera, speaking into the mic, entering a PIN, etc. The UAF protocol allows the service to select which mechanisms are presented to the user.Once registered, the user simply repeats the local authentication action whenever they need to authenticate to the service. The user no longer needs to enter their password when authenticating from that device. UAF also allows experiences
Problems
http://www.zeropasswords.com/pdfs/WHATisWRONG_FIDO.pdf
Solutions
References
- Also see the page FIDO U2F for the 2nd factor description.