4 ms·
Honestly curious, what should we use?
by markild 10y ago
Honestly curious, what should we use?
- ashitlerferad 10y agoPublic-key crypto. Client side X.509 certificates for the web. S/MIME and OpenPGP keys for email. OpenSSH keys for SSH. etc
- mrsirduke 10y agoWe tried using X.509 certificates in Denmark for proving your identity to the state. It was a complete nightmare unless you understood what public key crypto is, how it works, and how to configure your browser for it. Don't get me started about having to move your certificate/keys around. It doesn't work for the masses.
- ashitlerferad 10y agoSo when are the browser vendors going to fix their interfaces?
- technomancy 10y agoThere's a world of difference between a well-designed pubkey interface like ssh-agent and what you get in today's browsers. I don't know how feasible it would be to replace passwords for the general public, but if browser vendors were actually serious about security, they could go a very long way towards making client certs feasible just by giving up on their current strategy of putting their fingers in their ears and pretending it doesn't exist.
- JorgeGT 10y agoSomething similar in Spain, your mandatory ID card is a smart card, and you can also ask for free personal certificates from the Royal Mint. Works really great to do paperwork from home, but only a minority uses it.
- laxatives 10y agoI'd love it if every time I wanted to log in, I entered my username/email, saw a two factor-auth, and had an email sent with a time sensitive link containing my session credentials. But this would be a pain in the ass if I had a slow connection or used an old email address. And worse, it be totally unsafe if I could (easily?) change the email address attached to the account.
- kkhire 10y agomagic link. That's what medium does for email logins, and slack offers the option as well. it's easily one of the safest methods
- arianvanp 10y agoThough slack magic links always stay valid... Leaving a nice plain text password for all MTAs that forward my mail.
- markild 10y agoAh.. Yes, but that will leave anyone that has somehow gotten access to my mail to suddenly have access to all my accounts then, wouldn't it?
- ascorbic 10y agoThey already do if they have password reset over email. That's why you need 2FA.