Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because my mother doesn't give two shits about public/private key. She just wants to authenticate and the easiest way both logistically and mentally to do that is to just sign into her email.

I fully support this idea from Mozilla and I hope it kills OpenID, as even that's a pain in the ass sometimes.



Surely the real win here is the massive reduction in password re-use on 'less secure' environments.

Obviously google/microsoft etc are not immune to screwing up and having their database hacked - but I'd rather put all my eggs in that basket than having a single egg in lots of baskets with differing levels of security that subsequently enable access to all of my eggs anyway and...

Yeah. So the eggs metaphor doesn't really work. Sorry.


Your mom can treat keypair as just another password thing. With the nice exception that she would never have to type it, just click on "sign in as (name)" button and browser/GPG agent combo would do the rest.

I'd note there are tons of solutions involving key escrow, so synchronization and recovery are not problems.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: