Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

https://fidoalliance.org/ is a much better idea and worth investing in instead.

Passwords must die. We need to get to the point where there is a modular mechanism for authentication so that individual devs never are tempted to create a users table and add a note field for password storage.



From the video on this page[0], it took 12 steps to link a fingerprint with fido. That doesn't seem like a realistic solution.

[0] https://fidoalliance.org/adoption/videos


That's specific to that implementation.

1. Navigate to Settings, Finger Scanner, Pay with Paypal

2. Select Install FIDO Ready Support, then Install NNL fingerprint scanner

3. Select Link to Paypal, then Link Fingerprint

4. Login to paypal with username and password

5. Agree to terms

6. Swipe finger to link fingerprint

7. Install paypal app.

1 is obviously mandatory. 2 could be preinstalled. 3 could be combined, but is mandatory. 5 is stupid. 7 should be already installed if you use paypal.

End result: find the right settings area, select link fingerprint to paypal, login to paypal, swipe fingerprint to link, done.

Don't criticize FIDO based on some half-baked implementation. Any problems you have with the setup flow are either Paypal's fault or Samsung's.


That halfbaked implementation is the featured video on their website. As someone new to fido, I was trying to learn about it and their website was very confusing and this featured video wasn't a great example of the technology. Those are not good signs of the technology.


They're trying to point out that it's usable today with paypal and the S5. They have no control over the steps Paypal and Samsung require to set it up. And although the 12 steps or however many there are are not ideal, it's not as if they left the setup for the user to figure out; all you have to do is follow the video. You're making a huge deal out of some extra steps on a one-time setup.

Don't blame the technology or the FIDO alliance when that video is about the S5 and Paypal, and the video is hosted on Paypal's youtube account.

The new yubikey neo (as of October) supports FIDO, but I don't know about client (browser/mobile) support middleware, and it requires nfc or full sized usb.


Seems like an overcomplicated mostly analog authentication. The last thing I want is being locked out of an account due to failed fingerprint scan or similar. I'm personally okay with a system like 1Password married to 2FA, it just needs to be better integrated like with Chrome's Credential Manager API and similar.


What is analog authentication? FIDO is a general protocol, it doesn't mandate fingerprints or say how to recover if a fingerprint scan starts failing to match... that's up to the implementer (the site you're authenticating to). Watch some other videos or read more docs on FIDO for a better idea of how it works. It's a generic protocol for 2 factor authentication done right.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: