5 ms·
1. One difference is that a different key pair is used for every domain so you don't have to worry about your public key being used to uniquely identify you. Al
by romaimperator 15y ago
1. One difference is that a different key pair is used for every domain so you don't have to worry about your public key being used to uniquely identify you. Also, I think this is easier for novice users than creating a cert.
2. I plan on adding in an import/export feature for the next release.
3. This should be more secure than passwords because the only information that the server gets is your public key, which of course is assumed to be public knowledge. No more wondering if the website you're using is properly storing passwords.
Thanks for the questions.
- ef4 15y agoDo browser-generated SSL client certs really share keypairs between unrelated domains? AFAIK, each one asks the browser to generate a new keypair. Unless of course they've chosen to be federated with someone who has already issues you a cert.
- marshray 15y agoYes, browsers can be a bit promiscuous with who they hand your client cert to. It depends on the browser, who issued the cert, and what websites the user has agreed to supply their client cert for. If a specific website issued the cert, it won't be terribly useful to another site, but it could leak some personal info. If a well-known CA (e.g. DigiNotar) issued the cert, it might be valid across a wide range of sites (e.g. Dutch government and other sites). The TLS protocol is a bit lacking in this regard. A man-in-the-middle type attacker can impersonate a server to a browser and get the "public" client cert.
- 7952 15y agoCould you fit the private key in a QR code? http://bitbills.com/how http://bitbills.com/how