3 ms·
StartSSL (a reasonably priced Israeli PKIX CA) does. Some Banks do too, but tend to wrap it all up in a hardened browser instance or app. As for why no-one else
by phlo 13y ago
StartSSL (a reasonably priced Israeli PKIX CA) does. Some Banks do too, but tend to wrap it all up in a hardened browser instance or app.
As for why no-one else does:
* installing a client cert is way too complicated for "average" users
* being directed to change settings you don't understand may appear scary
* moving a your client cert from one box to another is unnecessarily complicated (browser sync may help there)
* if more than one person uses the OS account, they'll need to mess around in the browsers config option each time they authenticate
* not having to provide a password will "feel" insecure to many users
* running a PKI is hard[er than storing passwords]
* I'm not sure we want people installing any kind of certificates as a normal part of their workflow -- more often than not they might stumble upon a malicious CA cert