4 ms·
Why can't we use PGP tu login to websites? That way the server only has your public key (and everyone can have it anyway).
by faleidel 11y ago
Why can't we use PGP tu login to websites?
That way the server only has your public key (and everyone can have it anyway).
- ybx 11y agoFrom a usability perspective, it's probably because dealing with keys that can't just be memorized is hard for most people.
- faleidel 11y agoSeems like the solution already exist : password managers. But yes, having small memorizable passwords is much more convenient.
- scott_karana 11y agoCan you imagine how easy it would be with browser integration, though? :-) "The site is asking you to sign up. What secure login key would you like to use? * Personal * Office * Contracting"
- eximius 11y agoThis is what I am planning for a project of mine called AutoAuth. It's put on hold cause I have no idea how to write Chrome extensions.
- eximius 11y agoThis is what I am planning for a project of mine called AutoAuth. It's put on hold cause I have no idea how to write Chrome extensions.
- lsaferite 11y agoWhy even have those if you are, presumably, presenting yourself as the same person in each case? You are person 'A' and you have the private key (and maybe password used to unlock the key) to prove this fact. You don't need different private keys for each and the remote end just has a public key that says the account belongs to person 'A' and that key is public.
- scott_karana 11y agoI guess you're right. :-) The only usage case would be if someone wanted multiple accounts at the same site, and that would be rare indeed. The only other real concern, site hacks/collaboration leaking where you're a member of by public key, wouldn't be alleviated by merely a handful of keys anyways: you'd need unique keypairs for each to be truly secure.
- k3d3 11y agoMozilla Persona / BrowserID might be of interest to you.
- discreditable 11y agoSomething like HTTPS client certificates?
- Freaky 11y agoYou can use client certificate for authentication using TLS. The main difficulty is how dire the UI experience is on the browser side - it's evidently little more than an afterthought for vendors.
- dragonwriter 11y agoI think its a chicken and egg problem: very few services use it, so no browser vendor cares to improve the UX; and the UX sucks, so very few services choose to use it. It probably won't ever change unless one of the browser vendors that is also an vendor of popular online services decides that it would be good to enable it in its own services, and picks up the cost of upgrading its own UX to support that (creating pressure on other browser vendors, while also lowering the barrier for other online services.) The problem is that all of the browser vendors that could do it are pushing their own, online authentications schemes, and have no interest in client-based authentication.