7 ms·
> SSH Still requires a passphrase or initializing a keypair on the client & server. > HTTPS HTTPS requires user interaction when a site forgets to renew a ce
by wuunderbar 6y ago
> SSH
Still requires a passphrase or initializing a keypair on the client & server.
> HTTPS
HTTPS requires user interaction when a site forgets to renew a certificate.
Also SSH and HTTPS don't compare well. One does client authentication, the other doesn't.
- couchand 6y agoYou absolutely can do client authn in HTTPS, but it's rarely done outside intranet apps and high-security banking.
- lordlimecat 6y agoYour complaint about a login system is about its authentication, in a discussion on encryption and key exchange? The obvious point being made is that going from SMS -> E2E should be as seamless as from telnet -> ssh. SMS and messaging systems generally do require some level of authentication so you're making a ridiculous comparison.
- de_watcher 6y agoauth_pam/auth_basic in the nginx config and the http/https does authentication. And far less space to mess things up than with coding a fancy login page.