Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Caconym
Feb 12, 2013

Microsoft hasn't gotten their FIDO2-implementation notified as "authentication level high" according to EU eIDAS regulation, so anyone in the EU who wants to use FIDO2 and needs level high will need to have another FIDO2-implementation anyway.
We use a level high notified implementation (with yubikey 5-series) for PAM and are in the process of rolling it out to some other user groups this spring.

Adbot
ADBOT LOVES YOU

Caconym
Feb 12, 2013

SlowBloke posted:

EIDAS relies on known trust anchors based on conventional certs, fido will never get accepted in any LoA scheme since it would cut current CA providers out. I'm expecting eID ficep nodes to become an auth high anchor well before whitelabel fido keys become the norm.
EU Login does support fido already, albeit hidden very deeply, so it's not like they don't know it exists.

Being Norwegian I don't know about the intra-EU drama, but as I said, we use a commercial FIDO2 notified LoA High from Buypass.no.
They claimed to be the first to get there in january 22, I'd have thought there'd be more by now. Anyway, it is doable, at least when it's one of the current CAs like BuyPass that branch out. :v:

Google translated press release from last year here: https://www-buypass-no.translate.goog/nyheter/fido2-pa-hoyeste-sikkerhetsniva?_x_tr_sl=no&_x_tr_tl=en&_x_tr_hl=no&_x_tr_pto=wapp

Caconym
Feb 12, 2013


This is slowly getting better with more wireless stuff like Bluetooth sensors and such. Much of the outdated stuff is because of stringent regulations of "electromedical" devices, that is, stuff connected to the mains on one side, and to a patient on the other. Certifying that gear is expensive as gently caress, so once a hw-configuration is certified it will be static for the lifetime of the device, and not be compatible with newer OSes and such. But with Bluetooth you can air gap the patient from the mains, and thus run the sw on newer devices with less hassle while the patent sensors runs on batteries.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply