what best denote holding user authentication off-line?
i am building authentication client-server application, feedback i've viewed i should leave crush calculation server (it primarily implemented have fan accept hash, calculate crush client's entered password, review them). seems sense, nonetheless i am left problem -- how i justify users off-line?
for example, i deployed mobile device but internet access, many secure proceed hoop authentication?
the proceed i it, i have either grant fan accept crush + any salt information, use removed pin/password grant fan accept hash+salt that password.
i preference latter since seems border dispute settlement -- mobile device compromised, following confidence whole component (e.g. network-authenticated pieces) stays intact.
what best options considerations?
Comments
Post a Comment