Delivery-Date: Fri, 10 Jun 2016 21:59:18 -0400
Return-Path: <tor-talk-bounces@lists.torproject.org>
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on moria.seul.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.1 required=5.0 tests=BAYES_00,DKIM_SIGNED,
	RCVD_IN_DNSWL_MED,T_DKIM_INVALID,T_FUZZY_SPRM,T_RP_MATCHES_RCVD autolearn=ham
	version=3.3.1
X-Original-To: archiver@seul.org
Delivered-To: archiver@seul.org
Received: from eugeni.torproject.org (eugeni.torproject.org [138.201.14.202])
	(using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by khazad-dum.seul.org (Postfix) with ESMTPS id B81621E0080;
	Fri, 10 Jun 2016 21:59:16 -0400 (EDT)
Received: from eugeni.torproject.org (localhost [127.0.0.1])
	by eugeni.torproject.org (Postfix) with ESMTP id 44673E15A2;
	Sat, 11 Jun 2016 01:58:30 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1])
 by eugeni.torproject.org (Postfix) with ESMTP id 3AAF7E15A0
 for <tor-talk@lists.torproject.org>; Sat, 11 Jun 2016 01:58:23 +0000 (UTC)
X-Virus-Scanned: Debian amavisd-new at 
Received: from eugeni.torproject.org ([127.0.0.1])
 by localhost (eugeni.torproject.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id QbgahGjnZvRP for <tor-talk@lists.torproject.org>;
 Sat, 11 Jun 2016 01:58:22 +0000 (UTC)
Received: from mail-oi0-x22f.google.com (mail-oi0-x22f.google.com
 [IPv6:2607:f8b0:4003:c06::22f])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (Client CN "smtp.gmail.com",
 Issuer "Google Internet Authority G2" (not verified))
 by eugeni.torproject.org (Postfix) with ESMTPS id 32588E159F
 for <tor-talk@lists.torproject.org>; Sat, 11 Jun 2016 01:58:22 +0000 (UTC)
Received: by mail-oi0-x22f.google.com with SMTP id w5so58587185oib.2
 for <tor-talk@lists.torproject.org>; Fri, 10 Jun 2016 18:58:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=paragonie-com.20150623.gappssmtp.com; s=20150623;
 h=mime-version:date:message-id:subject:from:to;
 bh=24j3Vu5SbnjrIvzohdY4lpnIQAQwPBDEWUF1Sm6+qwk=;
 b=NaLFh4CH+3WfPLm/ogP4wTahLa2/ZrMyLZMqZSi2ONevrJjjQmqe4gNn86LbF3+WdX
 NKaTk5cchBckSWiW9A9dcfX5fzm59NSKJjuGbzwo/SSuGMuFw/i2E5xGcjyE+MxEYQJ3
 YGMWBngigds34KY4ngt+uqlw339eHw03hcEzo0R9mq3Xv6L8xO1hpRDW3VNlz/nIilWe
 MctWzIjOI1ogYWIScrgjvXXcyyhTmUZpJ64jzbRXYCe4Muuy3JdQnsoQK6zvXOgSIZpi
 77Br2kO6njafG+Xur3TXNQXrKF+6yNgyy6ny5lzws1LVfJqrNJ6oM6lWzX6w59OsC9nd
 Oj1Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20130820;
 h=x-gm-message-state:mime-version:date:message-id:subject:from:to;
 bh=24j3Vu5SbnjrIvzohdY4lpnIQAQwPBDEWUF1Sm6+qwk=;
 b=QNaC111fxYv+aN9u9OWJDVDKRbjKLYg7kDD6Lg42As2ASN5YOGJDH5D8gCQJrnUBpQ
 PUb/+ObpVtJ4vAyCuL1j+2AwAvuaxTPB7wOrkBigg6E6s5otQQpfa88s2BTSb2mhdgzw
 GgFtNwgtPk17RDAk+1EqHZU4NQka9XyVlXCwOeDJbsyKZz35Qem4q8x1BlRyVsUrgIMk
 8EYjMwPD44gpMJtTLlLR7mkWAAvvN0nguTaYgDuBxXcnV6Y3KTlU4OPM8cIbw0YzDzR0
 /ougP7DjqtvR7JNSrL7Q4hX7LIF8sWM/67yhIwk/K+//nNhikx71b79ClknzSKsslMBm
 t6Lw==
X-Gm-Message-State: ALyK8tJ0HAujT/8UVVLWUQ/LJ52ICaUKT+z2gXnJaa7Q8XP7/Gw8itKooU657TXcIcrYYm3+UTCcEP6L/LeZWA==
MIME-Version: 1.0
X-Received: by 10.157.51.74 with SMTP id u10mr2933144otd.124.1465610296942;
 Fri, 10 Jun 2016 18:58:16 -0700 (PDT)
Received: by 10.157.26.106 with HTTP; Fri, 10 Jun 2016 18:58:16 -0700 (PDT)
Date: Fri, 10 Jun 2016 21:58:16 -0400
Message-ID: <CAKws9z2UxNK0z9aKRSEoZLjYLj+mqCkgVOk9YN8Wa4Dgpk5gQg@mail.gmail.com>
From: Scott Arciszewski <scott@paragonie.com>
To: tor-talk@lists.torproject.org
X-Content-Filtered-By: Mailman/MimeDel 2.1.15
Subject: [tor-talk] Tor-Friendly Two-Factor Authentication?
X-BeenThere: tor-talk@lists.torproject.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: tor-talk@lists.torproject.org
List-Id: "all discussion about theory, design,
 and development of Onion Routing" <tor-talk.lists.torproject.org>
List-Unsubscribe: <https://lists.torproject.org/cgi-bin/mailman/options/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=unsubscribe>
List-Archive: <http://lists.torproject.org/pipermail/tor-talk/>
List-Post: <mailto:tor-talk@lists.torproject.org>
List-Help: <mailto:tor-talk-request@lists.torproject.org?subject=help>
List-Subscribe: <https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: tor-talk-bounces@lists.torproject.org
Sender: "tor-talk" <tor-talk-bounces@lists.torproject.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hi,

I'm developing a CMS platform called Airship and I'd like to make it
as Tor-friendly as possible.

Someone from the community suggested Two-Factor Authentication, but as
far as I'm aware there aren't many good options:

* SMS-based authentication requires a phone number, which is
identifying information
* Google Authenticator requires a Google Account, which now-a-days
requires surrendering your phone number to Google
* FIDO U2F requires users to purchase separate hardware devices which,
while cheap, aren't already in the arsenal of most netizens

I was curious if anyone in/around Tor was aware of any
privacy-preserving 2FA initiatives.

Thanks a lot,

Scott Arciszewski
Chief Development Officer
Paragon Initiative Enterprises
-----BEGIN PGP SIGNATURE-----
Version: Mailvelope v1.4.0
Comment: https://www.mailvelope.com

wsBcBAEBCAAQBQJXW3AsCRBrl6HCgmQE2gAA06YIAIx89seJ/M1Z+8V6+4sP
VRMCOcH2tPBbBl7KW17RRDuO2aoDsWNiaLNgY7ssHcm2xBte0T04uNTxfYxu
8/pzzgUrU6L7WHcUnGdUfqHtdBr6DY6xSrSavu6VwEATm0f5qDl3AouHyd9X
9aZs1nNX0/QQc/hMOE+hfkGl0rUDKKiwXCxLqXTxdxHiNqixQjb2GpfbiUen
ph4BLFAIFsUZ/STGRJOY31SVB/Lk9MOG2VOPlhXa27R+8IV7rcq41sQtEdUL
AdDOOCazmNISpUz1/I6/0wW16fGqrHk3jbtWMklzl4LI5aFg1w3CmV/MLEZE
i2HHPGvMiO3osSmyNBM2lL0=
=a2E8
-----END PGP SIGNATURE-----
-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

