Introducing 

Prezi AI.

Your new presentation assistant.

Refine, enhance, and tailor your content, source relevant images, and edit visuals quicker than ever before.

Loading…
Transcript

*****

More than

What?

one of these.

Hardware

Delivery

Software

2FA Config-o-matic

  • Something you know.
  • Something you have.

Virtual

Physical

2FA

  • Something you are.

157365

Strong Secret

No Secret

Public Delivery

No Delivery

When?

Second Factor

Completely Own

3rd Party

How

does it look

  • During login.
  • Before anaction.
  • Part of signup.

Authentication

Why not

Options

to a

User?

Tim Lytle

Why?

Picked by users.

mean

Do it all?

Online here.

@tjlytle

Passwords are hard.

Trade-offs.

Works here.

Static.

Used to work here.

Can be forgotten.

[Let's take a look at some code.]

Can Services make this easier?

github.com/nexmo/ToDo-Web

Rate this talk

https://joind.in/talk/7dcb0

Delivery

Challenge

Algorithm

Service compares

Sent using a

Service sends a

to range of values.

Requires active

separate channel.

signed challenge.

internet

User provides

connection.

Service generates

device's code.

Result of seed

single use code.

+ time. (TOTP)

Device identifies

OTP

request.

OTP

Or seed +

Challenge

157365

counter. (HOTP)

Response

Service verifies

Sibling

Returned over

Seed

codes match.

mobile app,

the authenticating

(and counter

approving

Requires

channel.

or time)

Returns

User ID

web login.

synchronization.

signed response.

Computationally

(number,

expensive.

email, etc)

Secret

One secret

per application

(or keypair)

or global.

But

does

Work?

how

it

Yes,of course.

Just

actions.

Learn more about creating dynamic, engaging presentations with Prezi