4 ms·
The security model based on passwords kept by site provider is totally broken. I, as a user, don't want to keep 20 different passwords for 20 different sites.
by zer0gravity 10y ago
The security model based on passwords kept by site provider is totally broken. I, as a user, don't want to keep 20 different passwords for 20 different sites.
What I want, is host my own security agent through which I can talk with any site. If I want to authenticate with site x, I simply point it to my security agent url and that's that. Open ID was/is an idea.
This approach will drastically lower the incentive for an attacker. Each attack will only get the data of one user, not millions.
- toyg 10y ago... Until the openid provider is breached, like LinkedIn was. Then you get access to everything for everyone. Decentralized schemes are safer overall. Ideally you want something like what LastPass does: local credentials replicated on the network in encrypted form. This way you take away responsibility for safe storage from unreliable websites, but you don't place the whole burden on the user (as the data is replicated and locked by a single password).
- zer0gravity 10y ago> What I want, is host my own security agent I don't trust third parties, no matter who they are. Technology can be developed so that the burden on the user is reduced, but nodoby wants to go there, because after all companies do want to have as many data about the user as they can...
- andybak 10y agoI don't trust 3rd parties but I do evaluate the threat that comes directly from large companies to be lower than the threat that comes from criminal hackers.
- theandrewbailey 10y agoThat's the idea behind cloud free password managers (like KeePass) and their browser plugins.