5 ms·
If you're submitting the same picture again and again then you might as well submit a cryptographically secure key (through some handshake, not necessarily uplo
by fundamental 5y ago
If you're submitting the same picture again and again then you might as well submit a cryptographically secure key (through some handshake, not necessarily uploading the key). If you're submitting images of the same physical object again and again, then you're in the domain of "is this match close enough". Deciding if something is close enough is non-trivial to compute and you end up leaking information about whatever you're taking pictures of.
Both cases seem worse than using a normal password or a more secure cryptographic key.
- xyzzy123 5y agoYep, changing the password UX is high friction because you need to teach everyone how it works and nobody's existing tools will work with it. If you're going to change this up it would make more sense to move to a better protocol than "provide this fixed shared secret". It's also useful to think about what the "root of trust" is in authentication flows. That is, the thing that can reset the password. This might reasonably be email, an OIDC provider or a cloud account linked to your device vendor. IMHO what would be really nice would be a decent ecosystem around WebAuthn. So ways to plug different providers into your browser / operating system. This would let you choose some combination of hardware keys, your preferred password manager or keys linked to your icloud/google account, for 1-click auth everywhere.