Hi again! I observe the HAS topic presented by You, and with each new post, I understand more and more, but still have a hole in knowledge. Could You share some online publications about out-of-band data ? Maybe it will be good to add some references about security topics mentioned here, to make the post more reliable.
Also, I have a question about malicious applications which sends requests for approval on behalf of other application, how does the HAS protocol prevent such an attack ?

Could You share some online publications about out-of-band data ?

Yes, more posts about it and how security is managed are coming... 😅

how does the HAS protocol prevent such an attack ?

That will be addressed in the coming posts too.
TLDR; auth_req sent by a malicious app to HAS will expire and be ignored if the user's PKSA is not running. If the PKSA is running, PKSA should ignore them if they did not retrieve a matching off-band auth_req_payload before.

What's the advantage of signing in with Hive Authentication Services instead of signing in with Keychain? Keychain also does the signing locally without sharing the keys to anyone. Would it be possible to collaborate with Keychain instead of building another login service?

The browser extension you are probably referring to in your comment does not work on mobile.

I am actively working with the Keychain team to support the HAS protocol in Keychain Mobile.
It will allow users to store their keys in one place (Keychain Mobile) and authenticate within any application that supports the HAS protocol, either a mobile, desktop, or website app, without installing anything else.

I was so excited to see this and hear your presentation at HiveFest. Are there plans for a Wordpress plug-in for us non devs? That would be a game changer for Wordpress users.

Thank you.

Are there plans for a Wordpress plug-in for us non devs?

Not that I know. But if you know people who have the skills to do it, don't hesitate to tell them about it. I will be happy to support it.


This is a very useful reference post. Ill come back to this when i am implementing it in an app i have been thinking about resurrecting from the Steem days.
One thing that always concerned me by being an app developer was having to be responsible for peoples private keys in some way. I'll take this for a test drive and see how it works.

Great to read you are interested to support HAS in your apps.
Feel free to contact me if you have any questions or need help.

How can I download it?
I can't find it in my app store

HAS is not a downloadable application