3 ms·
Is there any chance to go even further than this? I'm imaging a public key based authentication scheme. The user submit their public key to the server first, t
by nirui 5y ago
Is there any chance to go even further than this? I'm imaging a public key based authentication scheme.
The user submit their public key to the server first, then in the feature logins, server will generate a challenge for client to decrypt and respond.
Of course the browser can apply some UX magic at the client end, for example displaying a pop window to allow user to select a public key for the authentication process, etc.
- andreareina 5y agoIsn't that basically client certificates?
- jannes 5y agoSounds like client certificates. I guess you have never used those. All major browsers support them. In Firefox you can find them here: Settings -> Privacy & Security -> View Certificates -> Your Certificates
- nirui 5y agoYes, but the advantage is that the user sends their own public keys and they can switch it freely (and preferably easily, user click "login", a window pop up, user select a public key, done) at will. While client certificates is currently managed fully by the browser, and you need to adjust your HTTPS infrastructure in order to enable the feature.