rust-u2f
CozeJS
rust-u2f | CozeJS | |
---|---|---|
8 | 8 | |
285 | 5 | |
- | - | |
5.4 | 4.5 | |
3 months ago | about 1 month ago | |
Rust | JavaScript | |
Apache License 2.0 | BSD 3-clause "New" or "Revised" License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
rust-u2f
-
Software U2F with Fingerprint (On Linux)
This project aims to support U2F / FIDO2 using fingerprint reader on Linux (via libfprint). The goal is to have the same user experience with 2FA using Windows Hello.
This project is based on https://github.com/danstiner/rust-u2f with minor modification (see my fork: https://github.com/ngxson/rust-u2f-pkexec)
Link to the project: https://github.com/ngxson/softu2f-fprintd-docker
- The mechanics of a sophisticated phishing scam and how we stopped it
-
Apple, Google, and Microsoft commit to expanded support for FIDO standard
I've considered adding FIDO2 support to the software-only U2F token I wrote ( https://github.com/danstiner/rust-u2f). It's a fair bit of work though, and I am not sure how comfortable I am with passwordless login unless the keys are kept purely in hardware such as a TPM.
That said, my reading of this post is that FIDO2 support will get built into Chromium directly, which is itself open source. Or if you do want a hardware key but running open software, I'd definitely recommend https://solokeys.com/, I've been following them for a long time.
Also there was some related discussion on this same article last week: https://news.ycombinator.com/item?id=31274677
- Apple/Google/Microsoft to accelerate rollout of passwordless sign‑in standard
- Howdy – Windows Hello style facial authentication for Linux
-
Google is going to ban “less secure sign in method”
On a Workspace account you only need U2F token emulator (https://github.com/danstiner/rust-u2f woks fine) and thenn you can setup u2f first and add normal TOTP in second step. But u2f must stay there. I don't have a personal account to try if it works the same.
-
Ask HN: Is Google phasing out Authenticator/TOTP?
As it becomes easier to emulate hardware tokens[1], Google may start limiting which ones it accepts. I believe they can use attestation keys to do that.
This is just a softer layer of security to slow down less sophisticated mass signup attempts.
They may very well eventually phase out TOTP, under the justification that it is not as secure, but I would be shocked if they ever retire the highly insecure SMS verification.
TOTP is really easy to implement, and adds a ton of value. I have a oneliner that takes a screenshot, extracts the QR code with zbarimg, and adds it to my pass[2] password database, which then hooks back into my browser. I use it whenever it is available because it is so low effort.
[1]: https://github.com/danstiner/rust-u2f
-
Does 2FA actually prevent phishing?
GitHub has a couple of others listed, but I have not tested them personally: Example https://github.com/danstiner/rust-u2f
CozeJS
-
Introducing Coze - a cryptographic JSON messaging specification
Coze is open source under the BSD 3 license and has a reference implementation is written in Go. There's also a Javascript implementation and a CLI library.
-
Show HN: Coze – cryptographic JSON messaging specification
We've also published a [Javascript implementation of Coze](https://github.com/Cyphrme/CozeJS) and a [CLI library](https://github.com/Cyphrme/CozeCLI).
We hope you enjoy!
# What is Coze useful for?
-
Coze: a cryptographic JSON messaging specification designed for human readability
We've also published a Javascript implementation of Coze and a CLI library.
-
How to store your app's entire state in the url
https://convert.zamicol.com/#?inAlph=Text&in=Hello%20world!&...
https://cyphr.me/ed25519_applet/ed.html#?msg=Hello%20World!&...
https://cyphr.me/coze?verify&input={%22pay%22:{%22alg%22:%22...
- Hi , I'm using laravel as an api with react js and I want to implement JWT in my project. I heard about laravel passport, sanctum and other libraries like jwt-auth ? I don't know which one is better and what do you recommend?
- Cyphrme/Cozejs: Coze Javascript
-
Apple, Google, and Microsoft commit to expanded support for FIDO standard
Hello, it's me again.
We just made public the java script implementation of Coze.
https://github.com/Cyphrme/cozejs.
What are some alternatives?
OpenSK - OpenSK is an open-source implementation for security keys written in Rust that supports both FIDO U2F and FIDO2 standards.
calculang - calculang is a language for calculations 🧮💬👩💻
secretive - Store SSH keys in the Secure Enclave
u - μ is a JavaScript library for encoding/decoding state (JavaScript object) in URL
Coze - Coze is a cryptographic JSON messaging specification.
brotli-wasm - A reliable compressor and decompressor for Brotli, supporting node & browsers via wasm
wasmer - 🚀 The leading Wasm Runtime supporting WASIX, WASI and Emscripten
t
solo1 - Solo 1 firmware in C
CozeCLI - Coze CLI
tokei - Count your code, quickly.
pastml