New incubation: Origin-bound one-time codes delivered via SMS

Hi all,

I wanted to let WebAppSec know about a new incubation Sam (CCed) and I
are editing that I think some of you may find interesting.

It's a proposal for a lightweight text format that websites may use for
delivering one-time codes over SMS, and for associating such codes with
the website's origin. Here's an example:

    747723 is your ExampleCo authentication code.
    
    @example.com #747723

Useful links:

* Explainer: https://github.com/WICG/sms-one-time-codes/
* Spec: https://wicg.github.io/sms-one-time-codes/
* Issue tracker: https://github.com/WICG/sms-one-time-codes/issues/
* GitHub repository: https://github.com/WICG/sms-one-time-codes/

I'm happy to discuss the proposal here on public-webappsec, but I think
it would be better for folks to file issues with any questions,
concerns, or suggestions. That way folks who aren't on or aware of this
list can see and discuss any issues we identify.


Thanks,
Tess

Received on Friday, 17 April 2020 23:32:45 UTC