5 ms·
HTTP basic auth, TLS with client certs.
by shadowbanned4 3y ago
HTTP basic auth, TLS with client certs.
- dboreham 3y agoThose things don't do what OIDC does?
- shadowbanned4 3y agoThey do them with much less complexity than OIDC.
- krooj 3y agoThey absolutely do not and also introduce a significant amount of overhead with respect to key/certificate management.
- chucke 3y agoAnd security (basic auth is as good as sending clear text passwords).
- Nextgrid 3y ago> sending clear text passwords Which is totally fine to do over HTTPS.
- ustolemyname 3y agoPasswords need to be sent both with the request, and to the requestor. I think GP is referring to sending credentials to the service making the request. It is far better to give service XYZ a time-bound and scope limited token to perform a request than a user's username and password.
- EthanHeilman 3y agoIsn't Google moving toward phasing out TLS client certs in chrome/chromium?
- jeroenhd 3y agoDo you have any source for that? I can't find anything online about this, but that would effectively kill browser mTLS.
- EthanHeilman 3y agoChromium removed support for generating TLS Client Certs within chrome in 2016 [0] and ever since then it has gotten harder and harder to use mTLS in Chrome/Chromium. Ten years ago it wasn't a great UX, but now it isn't even obvious how to use it. The impression I've gotten is that Chrome isn't interested mTLS. [0]: https://groups.google.com/a/chromium.org/g/blink-dev/c/z_qEpmzzKh8/m/2hkaJdtsCAAJ https://groups.google.com/a/chromium.org/g/blink-dev/c/z_qEp...