3 ms·
What I'd really prefer to see is to simply never send my password over the wire to a website. I don't want to have to place any trust in them. When I log into
by jamoes 14y ago
What I'd really prefer to see is to simply never send my password over the wire to a website. I don't want to have to place any trust in them.
When I log into an SSH server, I am authenticated using purely my private and public keys. The SSH server has my public key, and my computer has my private key. A password is never sent over the wire, which doesn't give an adversarial SSH server the opportunity to store a password. And, if the SSH server is compromised, it doesn't even really matter - all the attacker gets is my public key.
Why isn't this authentication mechanism standard for the web? And, why isn't anyone even talking about building something like this? I'd much rather see browsers implement public key authentication than things like Persona or OpenID.
- mkup 14y agoSSL client side certificates are already implemented, but they have their own problems: 1) UI is hard to use http://pilif.github.com/2008/05/why-is-nobody-using-ssl-client-certificates/ http://pilif.github.com/2008/05/why-is-nobody-using-ssl-clie... 2) Can be easily stolen by malware (if client certificate is password-protected then password can be locally bruteforced on attacker's system) 3) It's not easy to switch identities (if you have multiple accounts on some website). And whenever there is no support for multiple identities, there is a ground for privacy concerns. 4) It's almost impossible to enter them from keyboard. How do I enter one on the iPhone? How do I write it on paper? What if I need to access some website from work and from home? What if my USB thumbdrive with client SSL certs fails or gets stolen? 5) They expire eventually, and when they do, users have another out-of-common-sense problem to solve. So, implementation already exists but it's impractical.
- jamoes 14y agoOh cool, I wasn't aware of this. SSL client side certificates are not quite the same as the public key authentication done using SSH, but it seems like it could still be workable if the UI weren't so awful. The only real concern seems to be the UI. Issue number 2 (being stolen by malware), could also easily occur with current authentication schemes (malware could steal the cookies on your machine, which would give it indefinite access to all sites you use until you change your passwords on them). All the other issues you mention are really just UI and UX problems. Another problem is the lack of a real name. "SSL Client Side Certificates" isn't short and catchy, like OpenID or Persona.