TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

CaptureIn - passwordless authentication

2 pointsby tomaacover 11 years ago

1 comment

nlyover 11 years ago
Except for the &#x27;revocation code&#x27; briefly mentioned on their FAQ page[0], this is likely just the same authentication scheme offered by Clef[1], with all the same inherent weaknesses.<p>The biggest weakness in these schemes is the inherent potential for a MITM to display the QR or bar code (I still don&#x27;t think Clef actually displays what site you&#x27;re logging in to on your phone, and even if they do it&#x27;s vulnerable to visually similar URLs). The bottom line is the lack of authentication between the phone and the browser.<p>The on-device encryption is also useless because the key is such a short PIN.<p>[0] <a href="http://www.capturein.com/FAQ.html" rel="nofollow">http:&#x2F;&#x2F;www.capturein.com&#x2F;FAQ.html</a> [1] <a href="https://getclef.com/" rel="nofollow">https:&#x2F;&#x2F;getclef.com&#x2F;</a>