4 ms·
Public key is a solution, or at least a huge detriment, to social engineering. The problem with passwords is they're fixed; once an attacker gets it they're in
by sysop073 18y ago
Public key is a solution, or at least a huge detriment, to social engineering. The problem with passwords is they're fixed; once an attacker gets it they're in forever. If we used asymmetric crypto to login to websites people wouldn't even have to know how it works. Instead of a password text field on a website there would just be a button, and the site would do a check with your browser to make sure you have the private key corresponding to the public key they have for your account. People wouldn't even have to know what a private key is, let alone where it's stored on the disk to give to somebody asking for it
- sfg 18y agoThe problem is the lack of convenience when you are away from your primary computer. Having to take a memory stick everywhere to login to websites is going to annoy a lot of people an awful lot.
- Hexstream 18y agoAlso, if you plug that memory stick in a computer you don't own then that computer can read all the private keys you have on it... and possibly forward it to an attacker.