|
|
|
|
|
by tialaramex
2377 days ago
|
|
Although the typical design for a FIDO key uses what is technically a symmetric ("secret") key that's an implementation detail and the purpose of the FIDO device is to maintain asymmetric (private) keys. If you've been under the impression that FIDO is just a shared secret system like TOTP then I've got great news, it's much cleverer than that. By not relying on secrets the system is robust against total incompetence by a relying party. If say Facebook paste all the U2F credentials they have for your account into a public Pastebin, not only can that not be used to attack your Login.gov account secured with the same FIDO key, it can't even be used to attack the Facebook account the credentials are for. Military intelligence services actually rely heavily on analysis of public information. The value of the exciting and expensive Hollywood-style secret agent is mostly in their ability to do stuff, mostly illegal and immoral stuff, not a benefit to collecting intelligence. |
|
Open source is useful, to be sure, but so are informants / agents, and the safety of those sources and their continued usefulness is completely dependent upon secrecy. If that's too Hollywood then consider undercover law enforcement.