I was messing around and hacked together an authentication protocol that lets you sign in using image uploads. No form fields, no passwords, no 3rd party accounts. Sign in simply by uploading an image from your phone/computer.
Wanna hear your thoughts. I'm sure you smart folks can come up with something even more convenient and usable.
More info here: http://www.paweljaniak.co.za/2018/03/10/paveasy-a-frictionless-authentication-protocol/
I think uploading an image as an authentication scheme has a lot of friction for the end user. What if I want to login in my phone? Or another computer? It's hard to transfer the image as opposed to traditional passwords or email links.
However, I think something like this is great for custom QR code-like identifiers that could make an app experience a little bit more unique. This would be similar to how the FB Messenger and Snapchat QR codes work.
https://blog-trycontechnologi.netdna-ssl.com/blog/wp-content/uploads/2016/04/facebook-messenger-code-4.png?x39658
Agreed that the transfer of images is a big limitation. But if your phone is your primary device and a site allows you to generate a temporary PIN from your phone's session that you can enter on a computer (ala Google Authenticator) that takes care of the problem.
This kind of reminds me of Clef before they closed it, only in reverse. I miss them.
That looks great, if not a little bit complicated to understand, sad that they shut down.
I agree that it was hard to understand, which is what I think killed it. I'm telling you though... Waving your phone at your computer to get logged in to a website was like magic... lol!
Authentication has a long way to go. Passwords are far from a perfect solution. I just finished a contract with a large insurance company. When I walked past people's desks I saw tons of sticky notes with passwords written down. It's a security nightmare.
We need a better solution and I'm glad to see folks are still working on the problem! A lot of people are talking about biometrics, but as long as they don't offer the same legal protections (in the US) as a password I can't see myself switching over.