Boston Linux & Unix (BLU) Home | Calendar | Mail Lists | List Archives | Desktop SIG | Hardware Hacking SIG
Wiki | Flickr | PicasaWeb | Video | Maps & Directions | Installfests | Keysignings
Linux Cafe | Meeting Notes | Blog | Linux Links | Bling | About BLU

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] eliminating passwords



On 07/28/2013 11:49 PM, Tom Metro wrote:
> Elsewhere today there was a thread mentioning StarSSL. They take an
> interesting approach to site security. They don't use passwords. As part
> of the process of getting your SSL certificate, they generate a
> client-side SSL certificate that you install in your browser.

Now I have to trust that my browser will keep that file securely. Steal 
that file and you are in.  It doesn't solve the problem, but shifts it 
to a little used feature browser that is likely little audited for 
security and might be full of holes.

-kb



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org