2

I've been studying the OPAQUE protocol, and I like it (so far).

The RFC suggests using Argon2 as the Key-Stretching Function. Argon2 can take an optional "Secret value" (2, page 5).

I had the idea that that secret value could be provided by a Yubikey, so that the resulting OPAQUE protocol could use "something you have" (Yubikey) and "something you know" (password).

Is this possible? Is it even a good idea?

0 Answers0