[HN Gopher] Let's Authenticate: Automated Certificates for User ...
       ___________________________________________________________________
        
       Let's Authenticate: Automated Certificates for User Authentication
       [pdf]
        
       Author : runningmike
       Score  : 7 points
       Date   : 2022-04-30 20:49 UTC (2 hours ago)
        
 (HTM) web link (www.ndss-symposium.org)
 (TXT) w3m dump (www.ndss-symposium.org)
        
       | dane-pgp wrote:
       | > Numerous participants in our survey indicated a preference for
       | not being required to use a smartphone, hardware token, or
       | browser extension. We thus aim to allow users to use either a
       | smartphone or a browser extension, based on their preference,
       | expanding on our original design that focused exclusively on a
       | smartphone. We also note that a browser could directly implement
       | our system, avoiding the need for an extension.
       | 
       | I'm glad they captured this design requirement. There is a real
       | danger that future global auth systems will move towards a root
       | of trust which is even more oligarchic than the Web PKI model of
       | certificate authorities, namely the FIDO Alliance device
       | attestation/revocation system, or relying on the TPM systems of a
       | few OS/CPU manufacturers.
        
       ___________________________________________________________________
       (page generated 2022-04-30 23:01 UTC)