{"type":"rich","version":"1.0","author_name":"npub1uvtfvcegcn9kds68r8he57emc480vqtx8t22kpsctxgjxae44gvsksaxrt","author_url":"https://nostr.ae/npub1uvtfvcegcn9kds68r8he57emc480vqtx8t22kpsctxgjxae44gvsksaxrt","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2013-11-02\n📝 Original message:On 2 November 2013 14:02, Mike Hearn \u003cmike at plan99.net\u003e wrote:\n\n\u003e On Sat, Nov 2, 2013 at 6:01 AM, \u003cbitcoingrant at gmx.com\u003e wrote:\n\u003e\n\u003e\u003e In brief, the authentication work as follows:\n\u003e\u003e\n\u003e\u003e\n\u003e\u003e\n\u003e\u003e Server provides a token for the client to sign.\n\u003e\u003e\n\u003e\u003e client passes the signed message and the bitcoin address back to the\n\u003e\u003e server.\n\u003e\u003e\n\u003e\u003e server validates the message and honors the alias (optional) and bitcoin\n\u003e\u003e address as identification.\n\u003e\u003e\n\u003e\n\u003e http://pilif.github.io/2008/05/why-is-nobody-using-ssl-client-certificates/\n\u003e\n\nI actually use client certificates for almost all of my authentication.\n\nIt's true that the browser manufacturers have created an UX which is not\nideal, and very little effort is made to improve it.  But it is possible.\nSee this project from Mozilla labs.\n\nhttp://www.azarask.in/blog/post/identity-in-the-browser-firefox/\n\nUnfortunately this got killed :(\n\nMore popular is the trusted third party model like OAuth or Persona.\nThere's a conflict of interest as well, because browser manufacturers are\noften identity providers too, so there is an incentive to push TTP\ntechnology.\n\nThere's two elements here.  One is paswordless login (which I love).  The\nother is who controls your identity.  I like to control my own identity (in\nmy browser) using PKI.  But facebook and the big webmail providers have a\nlions share of the market.\n\nThe way to shift the balance is to offer the right incentives.\n\n\n\u003e\n\u003e\n\u003e ------------------------------------------------------------------------------\n\u003e Android is increasing in popularity, but the open development platform that\n\u003e developers love is also attractive to malware creators. Download this white\n\u003e paper to learn more about secure code signing practices that can help keep\n\u003e Android apps secure.\n\u003e http://pubads.g.doubleclick.net/gampad/clk?id=65839951\u0026iu=/4140/ostg.clktrk\n\u003e _______________________________________________\n\u003e Bitcoin-development mailing list\n\u003e Bitcoin-development at lists.sourceforge.net\n\u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development\n\u003e\n\u003e\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20131102/1aaf3dcc/attachment.html\u003e"}
