{"repo":"Acorn221/CubeAuthn","free":true,"listed":false,"github":"https://github.com/Acorn221/CubeAuthn","clone":"git clone https://github.com/Acorn221/CubeAuthn.git","description":"Rubiks cube based passkeys","language":"TypeScript","stars":21,"topics":["cube","extension","extension-chrome","rubiks","webauthn","webauthn-demo"],"license":null,"category":"auth-billing-email","readme_excerpt":"CubeAuthn CubeAuthn transforms a Bluetooth-enabled Rubik's cube into a WebAuthn-compatible authenticator by using the cube's physical state to deterministically generate cryptographic keypairs for passkeys. Here's the link to the paper [!Note] Check out the demo video to see it in action or get it here on the Chrome Web Store! [!WARNING] This is a proof-of-concept implementation. Currently only supports the GAN 356 i3 smart cube and this implementation is not secure and cannot be made secure with the current firmware of the GAN365 i3 as it broadcasts weakly encrypted messages, including the cube state, along with other issues which make it not practical for real world use. Overview Unlike traditional security tokens that store credentials, CubeAuthn uses the cube's physical state (one of 43 quintillion possible configurations) as part of a cryptographic seed. Keys are generated deterministically only during authentication, eliminating persistent credential storage. Features - WebAuthn/FIDO2 compatible - works with any passkey-enabled website - Deterministic key generation from cube state + secret - No credential storage - keys exist only during authentication - Optional Chrome sync/local support for secret - Scramble verification before authentication Security Model CubeAuthn explores a different approach to authentication security: - No persistent keys : Cryptographic material is generated on-demand and never stored - Physical dependency : Requires the cube in the exact phys","default_branch":null,"files":null,"tree":[],"storefront":"/r/Acorn221","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Acorn221/CubeAuthn/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}