Bitcoin Forum
April 19, 2024, 11:43:06 AM *
News: Latest Bitcoin Core release: 26.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: My 2 Factor Authentication System  (Read 1013 times)
indicasteve (OP)
Full Member
***
Offline Offline

Activity: 140
Merit: 100



View Profile WWW
November 10, 2011, 11:10:21 AM
 #1

Hi folks!

I've been working on an idea to provide an inexpensive 2 factor authentication system to websites.

Websites can hook into the APIs to easily provide a card based second layer of authentication.

The APIs and more info can be found here: https://go2fac.appspot.com

It's easier to show how it works than to explain it, so I made an open source PHP/MySQL login system that uses the APIs.  That site can be found here: http://174.5.169.52/go2fac

Since I wrote it all by hand, there might still be some bugs and things are still a little rough around the edges, but you can get a good idea what it's all about.

I know there are a lot of skilled programmers around here and I'm looking for your input to improve the API services and the security of the sample PHP code. 

Maybe the whole idea of using a card based authentication is crap...idk.  But I'm interested to hear your thoughts.

Thanks guys!

Steve



 


Art Express!  Native American Art, Crafts and Weapons!  coingig.com/ArtExpress
1713526986
Hero Member
*
Offline Offline

Posts: 1713526986

View Profile Personal Message (Offline)

Ignore
1713526986
Reply with quote  #2

1713526986
Report to moderator
1713526986
Hero Member
*
Offline Offline

Posts: 1713526986

View Profile Personal Message (Offline)

Ignore
1713526986
Reply with quote  #2

1713526986
Report to moderator
1713526986
Hero Member
*
Offline Offline

Posts: 1713526986

View Profile Personal Message (Offline)

Ignore
1713526986
Reply with quote  #2

1713526986
Report to moderator
Activity + Trust + Earned Merit == The Most Recognized Users on Bitcointalk
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
indicasteve (OP)
Full Member
***
Offline Offline

Activity: 140
Merit: 100



View Profile WWW
November 10, 2011, 05:19:44 PM
 #2

hmm..over 60 views to my thread here and no replies from the peanut gallery?

I'm either doing something right, or doing something wrong I guess.

But, I will try and make it easy....

I made an account on my website at http://174.5.169.52/go2fac.

Let's pretend that my database got dumped and my username is steven and the password is also steven   All lower case.

Can you log into my account?  If you can, I'll give you a bitcoin or a hug or something. 

The code is all open, so maybe you can find a vulnerability?

Your comments and questions are always welcome!

Cheers!


Art Express!  Native American Art, Crafts and Weapons!  coingig.com/ArtExpress
indicasteve (OP)
Full Member
***
Offline Offline

Activity: 140
Merit: 100



View Profile WWW
November 13, 2011, 06:56:14 AM
 #3

I'd like to take some time and thank everyone who has helped me with this project so far.

I would like to give a special thanks to my girlfriend who has been keeping my friends company while I have been busy at my desk 'playing on my computer'.   She says she loves me so it must be true even though all my friends wear the same shade of lipstick as she does.  Go figure?

I would like to give a special thanks to my mom who leaves a tray of left-over food at the top of the basement stairs every Tuesday and Friday evenings.  Your cooking is the best mom!

I would also like to take a moment and thank my dad who kicks the tray of food down the stairs and yells, "When the fuck are you going to pick up this shit and get a haircut and get a real job you bum?"  Dad, your words of wisdom and encouragement will always inspire me.

Finally, I would also like to thank my government for all their help and support with education, business and economic development programs made available to people like me.   Without your assistance I would not be able to flounder in such a glorious cesspool of debt and misopportunity.

Due to the extreme volume of enquirers to this thread, I may not be able to respond in a timely manor.  Please send any additional messages to my automated personal assistant.

Most Sincerely,

Steve









Art Express!  Native American Art, Crafts and Weapons!  coingig.com/ArtExpress
Bitbird
Full Member
***
Offline Offline

Activity: 234
Merit: 100



View Profile WWW
November 13, 2011, 05:21:46 PM
 #4

Nice work! And great humor! Cool

Raoul Duke
aka psy
Legendary
*
Offline Offline

Activity: 1358
Merit: 1002



View Profile
November 13, 2011, 06:49:20 PM
 #5

WalletBit uses the same type of system, but instead of using it for 2 factor auth it uses the "Secure Card" to authorize transactions, instead of using the account password. You might want to have a look at it and I dunno, maybe exchnage some ideas with Kris.

And no, it's not a crap idea, banks use it all the time.

Also, you might want to move your thread to the Project Development forum https://bitcointalk.org/index.php?board=12.0 which is probably the best place for this thread. You'll get more replies there than on the Off-Topic section... or not...
btc_artist
Full Member
***
Offline Offline

Activity: 154
Merit: 101

Bitcoin!


View Profile WWW
November 15, 2011, 07:31:40 AM
 #6

Nice work!  On a practical note, decoding the six shapes seems to take too long in my opinion.  It just seems like too much work, which means users are not going to like it.

BTC: 1CDCLDBHbAzHyYUkk1wYHPYmrtDZNhk8zf
LTC: LMS7SqZJnqzxo76iDSEua33WCyYZdjaQoE
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!