3 ms·
The idea is that you're implicitly trusting the company (or website), as well as anyone who has (whether legit or not) access, to only keep that password in mem
by ybx 11y ago
The idea is that you're implicitly trusting the company (or website), as well as anyone who has (whether legit or not) access, to only keep that password in memory, and it's preferable to authenticate without requiring that trust.
- aggieben 11y agoI can agree to this: this allows a user to not have to trust that the company running the application set up password authentication properly. But still: I just can't get worked up about this at all. I'd rather see pgp get implemented in browsers before this.
- k3d3 11y agoYou can already use TLS client certificates - the UI is just terrible is all.