4 ms·
What you mean is not "passphrase keys" but "public/private keypairs", and it sounds like you are using an agent as proxy, so you only have to authenticate local
by toddkaufmann 14y ago
What you mean is not "passphrase keys" but "public/private keypairs", and it sounds like you are using an agent as proxy, so you only have to authenticate locally once.
This isn't an answer, but: password managers like LastPass can do this for the web. I let it generate secure passwords like "e^9u21$Fb%mJv"--in fact I don't know most of my passwords, it logs me in automatically, I just authenticate once with a passphrase. Highly recommended (integration with most browsers, other security features, see the website); definitely worth a look for the interface considerations alone.
The answer: it's probably too hard to get there from here now. Too many changes to UI's, re-education of users, and really they don't care if you have to type in a password every time or click an extra page.
Look at the popularity of decentralized private/public key trading with (e.g.) PGP. NOT. Sure, the paranoid elite have learned how to use the keyservers and mixmaster remailers, but there needs to be a killer UI that's simple enough (or maybe just smarter than the user) before people.. will... post to facebooks with it?
Client SSL certificates were supposed to be a thing once back in the 90's--everyone would have one, it would identify you to your bank uniquely, and everyone would be secure. I'm pretty sure the protocol still allows for it, but I think I only saw one website use/require it, and not sure it was this century.
- dpweb 14y agoBig ups! LOVE LastPass.
- bdunbar 14y ago> Look at the popularity of decentralized private/public key trading with (e.g.) PGP. NOT. Haw. At a previous employer, in 2001, we started a project to deploy PGP to everyone. The idea was we could encrypt our work, email, send files to customers ... the boss was _keen_ on the idea. Our customers liked the idea, some of them. We were acquired and our new owners were lukewarm to hostile about the idea and it was dropped. > but there needs to be a killer UI that's simple enough (or maybe just smarter than the user) before people.. will... post to facebooks with it? I think that's the key, right there. Make it simple, easier to use than userid/password.