Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Argh. Why am I so late to this thread?

This is possible. Your BrowserID provider can do public/private key auth. You could have an identity that is provided for (you could do this yourself on your own domain) that you authenticate to via a private key.

That's how flexible this protocol is. The provider has a huge range of discretion about how the account is authenticated.



The problem is, one can't own a domain, but only lease it for a time being. And one can't migrate between johnny@example.edu and john@example.org.

That's how inflexible this protocol is, compared with a simple keypair.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: