3 ms·
You can use client certificate for authentication using TLS. The main difficulty is how dire the UI experience is on the browser side - it's evidently little m
by Freaky 11y ago
You can use client certificate for authentication using TLS. The main difficulty is how dire the UI experience is on the browser side - it's evidently little more than an afterthought for vendors.
- dragonwriter 11y agoI think its a chicken and egg problem: very few services use it, so no browser vendor cares to improve the UX; and the UX sucks, so very few services choose to use it. It probably won't ever change unless one of the browser vendors that is also an vendor of popular online services decides that it would be good to enable it in its own services, and picks up the cost of upgrading its own UX to support that (creating pressure on other browser vendors, while also lowering the barrier for other online services.) The problem is that all of the browser vendors that could do it are pushing their own, online authentications schemes, and have no interest in client-based authentication.