Hacker News new | past | comments | ask | show | jobs | submit login

Or ditch site passwords and use public key authentication, like ssh has used for decades...



This is already built into all browser and works great, as client-side SSL certificates. Nobody uses it though because you can't trust users to manage their private keys properly.


Yes! What could be/are reasons to not do this?


This is the goal with WebAuthn and FIDO.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: