SQRL wan't wrong, it was early(sjg.io) |
SQRL wan't wrong, it was early(sjg.io) |
IMO both solutions are a lost cause. Hopefully I'm just cynical and something can be worked out.
I might be biased, I used the PPP Pam module on linux for years, until I moved to TOTP, and then eventually to pubkey-only.
That said, the design is far more advanced than the rolling disaster which is Passkey and it is much better suited for small Yubikey-type devices, where you could easily have unlimited site support. It also had intrinsic portability and advanced real-world security considerations, such as an attestation that instructed a server to disable weaker authentication methods, such as email or SMS (which is also a customer support disaster, but still...).
Ultimately, SQRL is an object lesson that the best technical design doesn't always win - it needs the right timing and robust community/corporate support.
Edit: Also, the (client) reference implementation was written in x86 assembly language for Windows. So I'd say the timing, support, and portability are all reasons for the lack of adoption.
I personally prefer using that system better than passkeys, at least with the email code I understand the security implications.
The tech is actually easier.
but compared to FIDO which existed when it was made, it’s pretty obviously “wrong”.