4 ms·
Yes, I also think that it could be achieved. The problem as everywhere is the adoption. When two or three big companies would stand behind it, it could be easil
by PythonicAlpha 12y ago
Yes, I also think that it could be achieved. The problem as everywhere is the adoption. When two or three big companies would stand behind it, it could be easily implemented and I really would like to see a scheme like that.
There are of course some questions, that also would need to be solved. For example: What if an other person has access to my computer -- than I still would need some kind of master-password that had to be remember-able. Also there must be methods, to transfer my keys to an other computer or to "copy" for example onto mobile devices.
The example of the SIM-card for banking just shows, that the "big security" is really a hard problem. Two-factor is one idea, but it is always a game where the attackers are hunting the defenders (or vice versa).
- davidkhess 12y agoIf the W3C and the major browser vendors could agree to the API and Keychain specifics, it would help a lot. So far, both the W3C and the browser vendors have been AWOL for the most part on real solutions to this problem. If you are interested, I'm looking for folks to help flesh it out and promote it. Any and all help is welcome!
- davidkhess 12y agoRe: shared device use, yes, you would continue to do password management best practices (fingerprint scans, master passwords, etc.). I see the transferability as an export/import format issue. W3C, browser vendors and password managers need to agree on a format for keychain export/import. Note that this technique could still be used in conjunction with multi-factor auth. Since it is just an evolution of passwords, those type of mechanisms are still relevant and compatible (though, eliminating knowledge factors should reduce need for a second factor).