[HN Gopher] Let's Authenticate: Automated Certificates for User ...
___________________________________________________________________
Let's Authenticate: Automated Certificates for User Authentication
[pdf]
Author : runningmike
Score : 7 points
Date : 2022-04-30 20:49 UTC (2 hours ago)
(HTM) web link (www.ndss-symposium.org)
(TXT) w3m dump (www.ndss-symposium.org)
| dane-pgp wrote:
| > Numerous participants in our survey indicated a preference for
| not being required to use a smartphone, hardware token, or
| browser extension. We thus aim to allow users to use either a
| smartphone or a browser extension, based on their preference,
| expanding on our original design that focused exclusively on a
| smartphone. We also note that a browser could directly implement
| our system, avoiding the need for an extension.
|
| I'm glad they captured this design requirement. There is a real
| danger that future global auth systems will move towards a root
| of trust which is even more oligarchic than the Web PKI model of
| certificate authorities, namely the FIDO Alliance device
| attestation/revocation system, or relying on the TPM systems of a
| few OS/CPU manufacturers.
___________________________________________________________________
(page generated 2022-04-30 23:01 UTC)