Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Right, that's exactly what I want. Or something like BrowserID / Persona was supposed to be. It has to be slick and frictionless, otherwise it won't stand a chance.

You know, there is a reason nobody uses client certificates...



Aye in the end I don't think the protocol itself matters as much as the concept of doing (asymmetric) auth in the browser rather than layered over http. Yelling "but it already exists! client certs!" is kinda unproductive, like you said there's a reason nobody uses them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: