4 ms·
Could we bootstrap this by starting with support in password manager browser plugins, rather than better UI support in browsers? Say Lastpass, KeePass, and 1Pa
by JackC 10y ago
Could we bootstrap this by starting with support in password manager browser plugins, rather than better UI support in browsers?
Say Lastpass, KeePass, and 1Password agree to support an open public-key auth protocol, where during signup if a site supports the protocol, your password manager will provide a public key instead of a password, and will then sign a challenge with that key during login.
Advantages:
- Progressive enhancement -- everyone doesn't have to switch at once. Switch if you already use a password manager and want to opt into better security. Start with power users and trickle down as the pattern establishes itself.
- Workflow -- my password manager is already necessary for me to log into most sites, so I'm already solving the problem of syncing the cert store everywhere I need it. My password manager is also already part of my UI flow whenever I'm asked for a new password. If anything this will simplify my life as a user, because server-side support will let my password manager offer better UI. (This would require some manual challenge response for the rare occasions I can't install the PM -- not sure how tricky that part would be.)
- Incentives -- supporting the protocol is a value add for password managers -- it's another way to get higher security by using the product.
I'm sure folks are ahead of me -- just tossing out this angle in case it's helpful.
- smoyer 10y agoI'd like a Keybase plugin that performed that function!
- geofft 10y agoSimilar ideas are the BrowserAuth stuff http://www.browserauth.net/ http://www.browserauth.net/ , which I think hasn't seen much activity, and FIDO https://fidoalliance.org/specifications/overview/ https://fidoalliance.org/specifications/overview/ . FIDO is focused more on using some authentication system (either a biometric reader, or a Yubikey or similar token), but I think you can just use "I am logged into this account on this computer" as your client auth backend.
- rlpb 10y agoI think Mozilla's Persona fixed this general problem even better. Client auth support could easily have been a part of that had they got further into the project. Unfortunately, there doesn't seem to be a business model around making this better. I think that password manager companies would be shooting themselves in the foot by doing this too. The reason they exist is because this kind of solution doesn't currently exist.
- sanderjd 10y agoI don't really understand the business model point - isn't it the same as the business model for any other browser improvement? Better browser -> more users -> ??? -> profit!
- mathgeek 10y agoI think one catch is that once a standard is in place, open source software will inevitably step in as a replacement for paid software.
- jimktrains2 10y agoThere was https://developer.mozilla.org/en-US/docs/Web/HTML/Element/keygen https://developer.mozilla.org/en-US/docs/Web/HTML/Element/ke... to help standardize a means of generating certs, but it's fallen by the wayside and never gained steam.