3 ms·
I think this is pretty the same thing as storing a secure cookie? Except the 'cookie' is the private key on the phone, so it's tied to the phone not to a parti
by jbert 13y ago
I think this is pretty the same thing as storing a secure cookie?
Except the 'cookie' is the private key on the phone, so it's tied to the phone not to a particular browser.
Other than that, I don't see a difference between the two?
I think this is basically a long-lived session cookie, stored out-of-band.
I also don't see how the public/private keypair changes anything. Why not just store the nonce on the phone? If the nonce has only ever gone over https to the user, no-one else will know it.