Seriously, why the hell are we still using username/password when browsers have supported requesting client certificates for years now.

Literally just learned today that it's an API that's supported in all the major browsers already. Maybe because it's at the TLS/Server-side layer instead of inside client-side JS or the HTTP layer?

Only downside is now I need to add this functionality to Agregore. :P


one more thing on this topic, what's cool is that of this is pretty much how the protocol handles authentication.

it happens at the tls level and means there's less stuff that you need to do to authenticate a session and manage credentials.

· · Web · 0 · 0 · 6
Sign in to participate in the conversation

Escape ship from centralized social media run by Mauve.