28 ms·
Oh cool, I wasn't aware of this. SSL client side certificates are not quite the same as the public key authentication done using SSH, but it seems like it coul
by jamoes 14y ago
Oh cool, I wasn't aware of this. SSL client side certificates are not quite the same as the public key authentication done using SSH, but it seems like it could still be workable if the UI weren't so awful.
The only real concern seems to be the UI. Issue number 2 (being stolen by malware), could also easily occur with current authentication schemes (malware could steal the cookies on your machine, which would give it indefinite access to all sites you use until you change your passwords on them). All the other issues you mention are really just UI and UX problems.
Another problem is the lack of a real name. "SSL Client Side Certificates" isn't short and catchy, like OpenID or Persona.