3 ms·
This can be easily done using openid. Openid providers are free to authenticate you any which way including exotic means like those. Here's an implementation
by kniwor 17y ago
This can be easily done using openid. Openid providers are free to authenticate you any which way including exotic means like those. Here's an implementation in private beta: http://pgpopenid.com/ http://pgpopenid.com/
- pyre 17y agoI'd really like to see more details about how they are implementing this, which that page provides none of, unfortunately.
- kniwor 17y agoYea... That page is next to useless. Had heard of them a while ago and thought they would have more write up then that on their home page. Anyway, this is very simple to do. You first create a server that can authenticate you just for itself over the web. You send it your id, it sends a random string. You sign it and send it a random string of your own. Server signs your random string and sends it back. You both know you are authentic, server leaves a signed cookie at your end. Now this server can act as an openid server too. You give random web-app your openid residing on this server... random web app asks this server. It confirms or denies and life is good.