12 ms·
Alternatively we could use public key cryptography and challenge-response protocol. Browser could generate a pair of keys during registration and send public ke
by jacekm 6y ago
Alternatively we could use public key cryptography and challenge-response protocol.
Browser could generate a pair of keys during registration and send public key to a server. While logging in server would send a token that would have to be signed with private key. Server would grant access upon verifying signature. Private keys should be password-protected and could be synced across devices via Chrome/FF account.
Or we could use WebAuthn. I am very curious whether it will get any recognition and support. I am definitely rooting for it.