4 ms·
As an alternative to this checkout TozID. The premise of their authentication model is to avoid sending the password all together and use public key crypto to
by edwardr 6y ago
As an alternative to this checkout TozID. The premise of their authentication model is to avoid sending the password all together and use public key crypto to sign and verify requests between the client and the auth server.
https://tozny.com/tozid/ https://tozny.com/tozid/
- jialutu 6y agoNice, thanks for this! I also found out that protonmail doesn't seem to send the password in plain text in the post request itself. Really keen to see how they do it as well.
- arghwhat 6y agoNote that such system only provides you benefit if the client-implementation is to be trusted. E.g., if your user-agent does it all for you, you could consider it trusted, but if all the code is provided by the "untrusted" service-provider that you won't want to see your password, it ends up just being for show. Similar situation with ProtonMail: As long as you use the clients shipped by them (webmail, app), all of the security hinges on nothing but a promise. Their app can read the passwords and keys as much as it wants.