“If you turn to page 524, you’ll see that we’ve very clearly provided the 47 different definitions of digital identity that exist today. So I’m not sure I understand your confusion”
@jgrantindc
Hi @chefsymon, eating @BBQMabels LV tonight and there is this nondescript door labeled “elevator”. People go in and never come out... #SoylentGreenIsPeople?
.@Google now lets you sign in to some services on Chrome on Android w/ just a fingerprint - a functionality built using #FIDO2. FIDO2 is "much more secure than regular passwords" & Google plans to add the functionality to more services in the future @verge https://t.co/rMI2CS7tbR
I just got approved to open up 17 new positions yesterday... IAM software manager / developers, security engineers, threat analyst, data engineer... anyone interested?
If you have installed OSX 10.15 (not something I am recommending quite yet) You may notice WebAuthn is not working by default in Safari 13. The version in the OS is a bit behind the technology preview, but can be made to work.
You can now use Web Authentication in @Firefox for Android Beta (68), enabled by default, powered by Android's #WebAuthn support! #CTAP2#FIDO Give it a try, file any bugs you find!
@nelsonmenezes@grigs I guess that might work. You would probably have to set the WebAuthn server's domain as <something>.ngrok.com so that it didn't think it was being phished.
@grigs@nelsonmenezes It's not the domain name that's the problem, it's having a valid SSL cert. You could probably setup dynamic dns and then use Let's Encrypt but that seems harder than setting up a server.
@grigs Happy to setup a screen sharing session and see if we can figure out how to get it installed. DM me if you're interested so that we can exchange contact info.
@grigs Sorry, I haven't read the whole thread. :)
I can help you get it running on a server if you want. (Should I admit that I'm currently using DigitalOcean instead of AWS?)
@grigs This is probably the hangup: WebAuthn requires you to be running in a "secure context", which is either connecting to "localhost" or a server with a valid SSL cert. If you install it locally you can only connect to it locally. Server with Let's Encrypt cert is your best bet.
Don’t want to have to carry around a security key? Now your Android phone IS your security key: https://t.co/KHSAvF9N5m. Oh, and if you happen to have a Pixel 3, it’s a Titan Security Key. #googlenext19
Safari on iOS 12.2 beta now has an experimental feature flag for WebAuthn. The API is there but no CTAP2 connection for NFC or other authenticators yet as far as I can see. Track the beta. It is progress.