|
|
|
|
|
by alphazard
286 days ago
|
|
> authentication targets are gated and only reachable by establishing a tunnel via some kind of forwarding? No, it's just how you authenticate with signing keys. Given that a secure channel has been set up with ephemeral keys, you can sign a commitment to the channel (like the hash of the shared secret key) to prove who you are to the other party. > let users authenticate via SSH and then return a short-lived token that can then be used to log into an application (or even a SSO service) This is exactly what I recommend. If everyone did this, then eventually then the browsers or 1password could support it. |
|
And WebAuthn is using FIDO2, it's not that different, it's just that WebAuthn adds some stuff like a relying party.