Bitcoin Forum
May 01, 2024, 11:36:24 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 [4] 5 6 7 8 »  All
  Print  
Author Topic: [ANN] Clef is secure two-factor authentication with no passwords or tokens  (Read 15145 times)
Clef (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
April 05, 2015, 12:45:09 AM
 #61

1714563384
Hero Member
*
Offline Offline

Posts: 1714563384

View Profile Personal Message (Offline)

Ignore
1714563384
Reply with quote  #2

1714563384
Report to moderator
1714563384
Hero Member
*
Offline Offline

Posts: 1714563384

View Profile Personal Message (Offline)

Ignore
1714563384
Reply with quote  #2

1714563384
Report to moderator
1714563384
Hero Member
*
Offline Offline

Posts: 1714563384

View Profile Personal Message (Offline)

Ignore
1714563384
Reply with quote  #2

1714563384
Report to moderator
Every time a block is mined, a certain amount of BTC (called the subsidy) is created out of thin air and given to the miner. The subsidy halves every four years and will reach 0 in about 130 years.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714563384
Hero Member
*
Offline Offline

Posts: 1714563384

View Profile Personal Message (Offline)

Ignore
1714563384
Reply with quote  #2

1714563384
Report to moderator
1714563384
Hero Member
*
Offline Offline

Posts: 1714563384

View Profile Personal Message (Offline)

Ignore
1714563384
Reply with quote  #2

1714563384
Report to moderator
1714563384
Hero Member
*
Offline Offline

Posts: 1714563384

View Profile Personal Message (Offline)

Ignore
1714563384
Reply with quote  #2

1714563384
Report to moderator
freemind1
Legendary
*
Offline Offline

Activity: 1526
Merit: 1014


View Profile
April 06, 2015, 12:15:07 PM
 #62

Very good article, this well explained and even new users can understand all information without problems. It seems much safer than Google Authenticator and from what i 've seen in the video is also simple to use.

Congratulations for your work and thanks for sharing.
coinking
Legendary
*
Offline Offline

Activity: 927
Merit: 1000


View Profile
April 06, 2015, 06:04:34 PM
 #63

We are featured on CoinTelegraph today  Smiley

Security Is More than a Password — It's a Signature


Great article Clef! It's nice to see the community support.

.TeleX  AI.
▄▄▄▄▄▄
▄████████████▄
▄████████████████▄
████████████████████
██████████████████████
████████████████████████
█████████████████████████
██████████████████████████
██████████████████████████
██████████████████████████
██████████████████████████
████████████████████████
██████████████████████
████████████████████
▀████████████████▀
▀████████████▀
▀▀▀▀▀▀
Store
▄▄▄▄▄▄
▄████████████▄
▄████████████████▄
████████████▀▀▀█████
████████████░░░░░█████
███████▀▀▀███▀▀▀▀▀██████
███████░░░░░██▄▄▄▄▄███████
███████▄▄▄▄▄██░░░░░███████
███████░░░░░██████▀███████
████████████▀░░░░░░░▀█████
███████████░░░░░░░░░▄█████
████████▀████████▄██████
█████▀░░░░░░░▀████████
████▄░░░░░░░░░██████
▀████▄███████████▀
▀████████████▀
▀▀▀▀▀▀
Send/Receive
▄▄▄▄▄▄
▄████████████▄
▄████░███████████▄
██████░███░█████████
███████░███░██████████
███████░░░██░███████░███
████████░░░█░░░██░███░████
████████░░░█░░░██░███░████
█████░██░░░██░██░░░█░░░███
█████░██░░░██░███░██░░░███
█████░██░░░██░███░██░░░███
███░░░██░███████░███░███
██░░░██░███████░██████
█░░░████████████████
░░░██████████████▀
▀████████████▀
▀▀▀▀▀▀
Trade
coinking
Legendary
*
Offline Offline

Activity: 927
Merit: 1000


View Profile
April 07, 2015, 08:32:54 PM
 #64

Nice article, it explains 2FA really well.

Hope to see Clef on more exchanges, used it on Koinify for the Factom Sale and it works a treat!

yeah, me too. Once you get it set up (which takes max 1 min) it works like a charm  Cool

.TeleX  AI.
▄▄▄▄▄▄
▄████████████▄
▄████████████████▄
████████████████████
██████████████████████
████████████████████████
█████████████████████████
██████████████████████████
██████████████████████████
██████████████████████████
██████████████████████████
████████████████████████
██████████████████████
████████████████████
▀████████████████▀
▀████████████▀
▀▀▀▀▀▀
Store
▄▄▄▄▄▄
▄████████████▄
▄████████████████▄
████████████▀▀▀█████
████████████░░░░░█████
███████▀▀▀███▀▀▀▀▀██████
███████░░░░░██▄▄▄▄▄███████
███████▄▄▄▄▄██░░░░░███████
███████░░░░░██████▀███████
████████████▀░░░░░░░▀█████
███████████░░░░░░░░░▄█████
████████▀████████▄██████
█████▀░░░░░░░▀████████
████▄░░░░░░░░░██████
▀████▄███████████▀
▀████████████▀
▀▀▀▀▀▀
Send/Receive
▄▄▄▄▄▄
▄████████████▄
▄████░███████████▄
██████░███░█████████
███████░███░██████████
███████░░░██░███████░███
████████░░░█░░░██░███░████
████████░░░█░░░██░███░████
█████░██░░░██░██░░░█░░░███
█████░██░░░██░███░██░░░███
█████░██░░░██░███░██░░░███
███░░░██░███████░███░███
██░░░██░███████░██████
█░░░████████████████
░░░██████████████▀
▀████████████▀
▀▀▀▀▀▀
Trade
Clef (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
April 08, 2015, 04:50:26 AM
 #65

Decentral Talk Live Ep #67: Brennen Byrne of Clef

Clef's CEO interviewed by Decentral.TV Talk Live during the 2015 Texas Bitcoin Conference.

https://i.imgur.com/99HIMni.png
btc_enigma
Hero Member
*****
Offline Offline

Activity: 688
Merit: 565


View Profile
April 08, 2015, 07:34:42 AM
 #66

tl;dr - to use Clef, you have to trust us, but public key auth is much harder to hack, so the overall security is way stronger

Do you offer a bare-bones open source client? I currently have no way of telling whether the private keys are being shared with your servers or whether they are only stored locally on my phone.

I'd be interested in knowing this too

I also don't see any options to back up my private keys.

What happens if I lose my phone?

This is very good question that I am also having. Your online documentation only talks about public key cryptography and says nothing about where the private keys are stored and their security. I guess the phone is generating a signature using the private key.

Can you put more detail on how this is secure:
  • How is the private key sandboxed? Since the phone is connected to internet , this is a concern for me. Other hardware devices like trezor or bank 2fa h/w devices  are not connected to internet , so it feels safer to me
  • Also I want to know, how are you getting enough entropy for the private key, is the implementation safe( We had same problem with other websites ). Can you open source this part

LOBSTER
Hero Member
*****
Offline Offline

Activity: 560
Merit: 500


View Profile
April 08, 2015, 10:11:05 AM
 #67

I think the project is pretty cool. What I like is a function to backup your data. For example if I would lose my phone with Google Authenticator, I could never access my funds on an online wallet like blockchain.info again...
coinking
Legendary
*
Offline Offline

Activity: 927
Merit: 1000


View Profile
April 08, 2015, 10:32:06 PM
 #68

Decentral Talk Live Ep #67: Brennen Byrne of Clef

Clef's CEO interviewed by Decentral.TV Talk Live during the 2015 Texas Bitcoin Conference.



Nice vid, it's good to see the faces behind Clef.

.TeleX  AI.
▄▄▄▄▄▄
▄████████████▄
▄████████████████▄
████████████████████
██████████████████████
████████████████████████
█████████████████████████
██████████████████████████
██████████████████████████
██████████████████████████
██████████████████████████
████████████████████████
██████████████████████
████████████████████
▀████████████████▀
▀████████████▀
▀▀▀▀▀▀
Store
▄▄▄▄▄▄
▄████████████▄
▄████████████████▄
████████████▀▀▀█████
████████████░░░░░█████
███████▀▀▀███▀▀▀▀▀██████
███████░░░░░██▄▄▄▄▄███████
███████▄▄▄▄▄██░░░░░███████
███████░░░░░██████▀███████
████████████▀░░░░░░░▀█████
███████████░░░░░░░░░▄█████
████████▀████████▄██████
█████▀░░░░░░░▀████████
████▄░░░░░░░░░██████
▀████▄███████████▀
▀████████████▀
▀▀▀▀▀▀
Send/Receive
▄▄▄▄▄▄
▄████████████▄
▄████░███████████▄
██████░███░█████████
███████░███░██████████
███████░░░██░███████░███
████████░░░█░░░██░███░████
████████░░░█░░░██░███░████
█████░██░░░██░██░░░█░░░███
█████░██░░░██░███░██░░░███
█████░██░░░██░███░██░░░███
███░░░██░███████░███░███
██░░░██░███████░██████
█░░░████████████████
░░░██████████████▀
▀████████████▀
▀▀▀▀▀▀
Trade
fordlincoln
Full Member
***
Offline Offline

Activity: 152
Merit: 100


View Profile
April 09, 2015, 07:16:05 PM
 #69

started using Clef and noticed that the app logs me out of everything when I'm asleep - it's a good feature and yea I know I should log out of everything when I leave the site but apparently I forget.

brennen
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
April 10, 2015, 12:31:18 AM
 #70


This is very good question that I am also having. Your online documentation only talks about public key cryptography and says nothing about where the private keys are stored and their security. I guess the phone is generating a signature using the private key.

Can you put more detail on how this is secure:
  • How is the private key sandboxed? Since the phone is connected to internet , this is a concern for me. Other hardware devices like trezor or bank 2fa h/w devices  are not connected to internet , so it feels safer to me
  • Also I want to know, how are you getting enough entropy for the private key, is the implementation safe( We had same problem with other websites ). Can you open source this part

Good questions Smiley

The private keys are generated and stored on the phone -- on iOS we get to use hardware encryption and on Android we use PIN-based encryption (though we're considering using something like Rivetz here).

We use the standard system libraries for both platforms to generate the keys which offer plenty of entropy for this kind of usage (http://android-developers.blogspot.de/2013/08/some-securerandom-thoughts.html -- the SecureRandom patch of course happening after August 2013).

As for being Internet connected -- when we talk about theoretical security, an Internet-connected phone will never provide the same level of protection as a dedicated offline device. That said, dedicated devices as they exist today are all seed-based (and so must have a server counterpart that stores the exact same seed and which IS Internet connected as well as centralized). A key based, dedicated offline device is definitely possible, but the infeasibility of distributing them along with the increased burden of training people how to use them make them pretty farfetched for a broad audience.
btchip
Hero Member
*****
Offline Offline

Activity: 623
Merit: 500

CTO, Ledger


View Profile WWW
April 10, 2015, 02:01:25 AM
 #71

That said, dedicated devices as they exist today are all seed-based (and so must have a server counterpart that stores the exact same seed and which IS Internet connected as well as centralized).

Do you know FIDO ? Devices are already available, cheap, extremely simple to use, and based on open standards.

btc_enigma
Hero Member
*****
Offline Offline

Activity: 688
Merit: 565


View Profile
April 10, 2015, 05:46:29 AM
 #72


This is very good question that I am also having. Your online documentation only talks about public key cryptography and says nothing about where the private keys are stored and their security. I guess the phone is generating a signature using the private key.

Can you put more detail on how this is secure:
  • How is the private key sandboxed? Since the phone is connected to internet , this is a concern for me. Other hardware devices like trezor or bank 2fa h/w devices  are not connected to internet , so it feels safer to me
  • Also I want to know, how are you getting enough entropy for the private key, is the implementation safe( We had same problem with other websites ). Can you open source this part

Good questions Smiley

The private keys are generated and stored on the phone -- on iOS we get to use hardware encryption and on Android we use PIN-based encryption (though we're considering using something like Rivetz here).

We use the standard system libraries for both platforms to generate the keys which offer plenty of entropy for this kind of usage (http://android-developers.blogspot.de/2013/08/some-securerandom-thoughts.html -- the SecureRandom patch of course happening after August 2013).

As for being Internet connected -- when we talk about theoretical security, an Internet-connected phone will never provide the same level of protection as a dedicated offline device. That said, dedicated devices as they exist today are all seed-based (and so must have a server counterpart that stores the exact same seed and which IS Internet connected as well as centralized). A key based, dedicated offline device is definitely possible, but the infeasibility of distributing them along with the increased burden of training people how to use them make them pretty farfetched for a broad audience.

Great. Good to know you guys have put enough thought into the security. Thumbs up for clef

bassguitarman
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500



View Profile
April 10, 2015, 06:45:14 AM
 #73

I did a little op-ed on clef, I hope you enjoy it

http://bitsofnews.net/more-than-just-an-authenticator/
coinking
Legendary
*
Offline Offline

Activity: 927
Merit: 1000


View Profile
April 10, 2015, 09:04:57 PM
 #74

I did a little op-ed on clef, I hope you enjoy it

http://bitsofnews.net/more-than-just-an-authenticator/

Nice article bassguitarman! Nothing like an outside review of a service. Cheers for that.

.TeleX  AI.
▄▄▄▄▄▄
▄████████████▄
▄████████████████▄
████████████████████
██████████████████████
████████████████████████
█████████████████████████
██████████████████████████
██████████████████████████
██████████████████████████
██████████████████████████
████████████████████████
██████████████████████
████████████████████
▀████████████████▀
▀████████████▀
▀▀▀▀▀▀
Store
▄▄▄▄▄▄
▄████████████▄
▄████████████████▄
████████████▀▀▀█████
████████████░░░░░█████
███████▀▀▀███▀▀▀▀▀██████
███████░░░░░██▄▄▄▄▄███████
███████▄▄▄▄▄██░░░░░███████
███████░░░░░██████▀███████
████████████▀░░░░░░░▀█████
███████████░░░░░░░░░▄█████
████████▀████████▄██████
█████▀░░░░░░░▀████████
████▄░░░░░░░░░██████
▀████▄███████████▀
▀████████████▀
▀▀▀▀▀▀
Send/Receive
▄▄▄▄▄▄
▄████████████▄
▄████░███████████▄
██████░███░█████████
███████░███░██████████
███████░░░██░███████░███
████████░░░█░░░██░███░████
████████░░░█░░░██░███░████
█████░██░░░██░██░░░█░░░███
█████░██░░░██░███░██░░░███
█████░██░░░██░███░██░░░███
███░░░██░███████░███░███
██░░░██░███████░██████
█░░░████████████████
░░░██████████████▀
▀████████████▀
▀▀▀▀▀▀
Trade
Clef (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
April 11, 2015, 12:49:17 AM
 #75

I did a little op-ed on clef, I hope you enjoy it

http://bitsofnews.net/more-than-just-an-authenticator/

We appreciate the support bassguitarman, good read!  Smiley

Are you planning to use or have been using Clef?
Clef (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
April 12, 2015, 05:20:16 PM
 #76

We are glad to be able to help improve security on Koinify.com.
Best wishes to both the Koinify and Factom teams with their ongoing Software Sale!


https://i.imgur.com/CKfrQHf.png

As featured on Bitcoinist.net
https://i.imgur.com/7hFexCS.png
coinking
Legendary
*
Offline Offline

Activity: 927
Merit: 1000


View Profile
April 12, 2015, 08:48:30 PM
 #77

We are glad to be able to help improve security on Koinify.com.
Best wishes to both the Koinify and Factom teams with their ongoing Software Sale!




As featured on Bitcoinist.net

 Looks like there's some good connections being made. Looking forward to more!

.TeleX  AI.
▄▄▄▄▄▄
▄████████████▄
▄████████████████▄
████████████████████
██████████████████████
████████████████████████
█████████████████████████
██████████████████████████
██████████████████████████
██████████████████████████
██████████████████████████
████████████████████████
██████████████████████
████████████████████
▀████████████████▀
▀████████████▀
▀▀▀▀▀▀
Store
▄▄▄▄▄▄
▄████████████▄
▄████████████████▄
████████████▀▀▀█████
████████████░░░░░█████
███████▀▀▀███▀▀▀▀▀██████
███████░░░░░██▄▄▄▄▄███████
███████▄▄▄▄▄██░░░░░███████
███████░░░░░██████▀███████
████████████▀░░░░░░░▀█████
███████████░░░░░░░░░▄█████
████████▀████████▄██████
█████▀░░░░░░░▀████████
████▄░░░░░░░░░██████
▀████▄███████████▀
▀████████████▀
▀▀▀▀▀▀
Send/Receive
▄▄▄▄▄▄
▄████████████▄
▄████░███████████▄
██████░███░█████████
███████░███░██████████
███████░░░██░███████░███
████████░░░█░░░██░███░████
████████░░░█░░░██░███░████
█████░██░░░██░██░░░█░░░███
█████░██░░░██░███░██░░░███
█████░██░░░██░███░██░░░███
███░░░██░███████░███░███
██░░░██░███████░██████
█░░░████████████████
░░░██████████████▀
▀████████████▀
▀▀▀▀▀▀
Trade
Clef (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
April 12, 2015, 11:40:51 PM
 #78

We are glad to be able to help improve security on Koinify.com.
Best wishes to both the Koinify and Factom teams with their ongoing Software Sale!


https://i.imgur.com/CKfrQHf.png

As featured on Bitcoinist.net
https://i.imgur.com/7hFexCS.png

 Looks like there's some good connections being made. Looking forward to more!

Make sure you listen in the coming weeks for more great announcements  Grin
FACTOM
Sr. Member
****
Offline Offline

Activity: 251
Merit: 250


View Profile WWW
April 13, 2015, 12:11:06 AM
 #79

We are glad to be able to help improve security on Koinify.com.
Best wishes to both the Koinify and Factom teams with their ongoing Software Sale!

We thank you for making the login process on Koinify easier and for the support!
valkir
Legendary
*
Offline Offline

Activity: 1484
Merit: 1004



View Profile
April 13, 2015, 12:54:15 AM
 #80

Great Job Clef Team! Its working perfectly!  Grin

██     Please support sidehack with his new miner project Send to :

1BURGERAXHH6Yi6LRybRJK7ybEm5m5HwTr
Pages: « 1 2 3 [4] 5 6 7 8 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!