3 ms·
Just out of curiosity, why aren't we using certificates for authentication instead of passwords by now? They can't possibly be worse overall, can they?
by dreish 17y ago
Just out of curiosity, why aren't we using certificates for authentication instead of passwords by now? They can't possibly be worse overall, can they?
- randallsquared 17y agoSeveral reasons. First, that's only useful for a single browser (or if the OS can manage the cert, a single computer or maybe domain account). Using certs, there's no easy way to login from your friend's house, or from the internet cafe. Second, it would have to be supported at the browser level well enough to be at least as easy as password usage, which is hard, since password usage is super-easy, as long as you choose a weak one (and people avoid sites that enforce good passwords, if they can). I'm using Safari, and I can't find anything about client-side certificates in the prefs. I know IE and Firefox support them fairly well, as I've used them for intranet sites in the past, but I don't think it's easy. Basically, the first time a site demanded a cert, the browser would have to walk someone through generating one, and it's hard to see how that could be made easy enough for people to sit through it. Third, any cert that has a password to unlock is going to be at least as difficult for the user as just using a password, and any cert which doesn't require a password will be vulnerable to being stolen by trojans, etc. You can get all the good things about using a cert by just making your site SSL-only and using a cookie, and this also avoids some of the bad things (inconvenience), but not all (vulnerability to trojans).
- ambition 17y agoEver check your email on a friend's laptop?