4 ms·
The is a great idea, but the usability is probably not good enough to make it work. What I like: I am authenticated by some proof of ownership, and, unlike wit
by struppi 11y ago
The is a great idea, but the usability is probably not good enough to make it work.
What I like: I am authenticated by some proof of ownership, and, unlike with password authentication, the "thing I own" is never transferred over a wire or stored at the server. This is even better than what I have now (unique passwords for every site, managed with 1Password, and 2FA for important sites).
But the SSH callback would have to be automatic - Via a browser plugin, or even better, implemented by the browser itself. I don't think I want to start a terminal and past a string every time I log in to a site.
The "paste this into your terminal" also opens up a completely different can of worms - Social engineering!
- merijnv 11y agoSo...basically you want SSL client certificates but with a slightly less sucky UI? I mean, https already supports this, it's just that setting up servers to deal with client certs sucks and the UI for users is also pretty bad. But the infrastructure is already there without poorly reinventing the wheel over SSH.
- struppi 11y agoRight, that's exactly what I want. Or something like BrowserID / Persona was supposed to be. It has to be slick and frictionless, otherwise it won't stand a chance. You know, there is a reason nobody uses client certificates...
- scrollaway 11y agoAye in the end I don't think the protocol itself matters as much as the concept of doing (asymmetric) auth in the browser rather than layered over http. Yelling "but it already exists! client certs!" is kinda unproductive, like you said there's a reason nobody uses them.
- ZeroMinx 11y agoI appreciate I'm a bit late to the party here, but.. Does anyone have any type of explanation of why the UI in browsers for client certs are so user-unfriendly? I would really like to use client certs more, but with things the way they are that's impossible right now. It's just too hard for a normal person to use them.
- dattl 11y agoMight be a stupid idea, but could you use Let's Encrypt Certs as client certificates? And the browser would generate a cert on it's own?
- WorldMaker 11y agoA few of the CAs have in the past offered certificates tied to personal email addresses for cheap as free for years in the hopes that S/MIME catch on. Those are typically fine for HTTPS client certificates too, but the bootstrapping problem is essentially the same for both. To date no one has really managed to get certificates easy enough to use for the average lay person nor adoption common enough for a lay person to need to overcome the learning curve.