Hacker News new | ask | show | jobs
by DanBC 4353 days ago
http://security.blogoverflow.com/2013/10/debunking-sqrl/

Sqrl looks to have some pretty bad flaws.

2 comments

That may be the most convicing bit in this article : http://attrition.org/errata/charlatan/steve_gibson/
Those are very bland and generic criticisms that can equally be leveled at many other authentication schemes.

Does this sqrl improve on the existing security offered by alternatives? Likely not. It just offers convenience and keeps many of the existing downsides.

Honestly 2/3 of those criticisms can be leveled at ANY single-sign-on scheme (Facebook, Google, Microsoft, etc). And the password reset issue would be trivial to engineer around.

So using it to explain why sqrl is a bad idea is a little confusing, are Google accounts also a bad idea?