4 ms·
The 'authentication' they've demonstrated there is completely broken, I hope this isn't in production anywhere.
by new_guy 5y ago
The 'authentication' they've demonstrated there is completely broken, I hope this isn't in production anywhere.
- G3rn0ti 5y agoCould you elaborate on why it’s so broken? The user signs a message with his private key, the backend verifies he signed the message using his public key proving the user‘s identity. I believe this being the same protocol as passwordless ssh. Maybe I am being naive but if everybody got a wallet i.e. a public/private key pair couldn’t this eventually replace passwords altogether?