Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To me, it's much more concerning that they do such a bad job of telling me what SQRL does than the fact that the page looks dated. At least it's clean-looking.

But I clicked around for a while and only found some videos that might show me what SQRL does, but I didn't actually feel like watching a video, so I still don't know.

Based on what I read, it sounds like snake oil so far. Too good to be true. I don't remember the phrase, but it suggested it would be my last password solution ever, which just sounds like snakeoil.

Also, it seems like only the Windows implementation is mature. All other implementations are by third parties and are marked as not being complete.



I would recommend reading through at least the first PDF on the site to get an idea of what it is and how it works. The short version is: It's a replacement password manager-esque protocol that enables logging into a web server while leaving no compromise-able secret in the servers database.

EDIT: A user posted a very nice write up of it in another comment: https://news.ycombinator.com/item?id=26314472




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: