Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's important to change your passwords at regular intervals, even if you use a secure one.

If you compare this to two factor authentication it's the same amount of extra work, but without the benefits.

You should also avoid copying passwords to the clipboard as many applications and even web sites might have access to it.

Too bad client certifications are deprecated, now when SSL/TSL is becoming more and more popular. Only downside with client certificates is that you have to copy the key (witch can be password protected) to all your devices. Another downside was that the site required SSL/TSL, but almost every site have that now!



There's also some privacy and UX concerns with client certs. See http://www.browserauth.net/tls-client-authentication

Personally I'd love to see UAF or SQRL take off. Lots of potential there.


most browsers will auto select the right cert. But for browsers that dont support the keygen tag you have to create the cert including priv key and pw. you can of course create many certs for different users, you can of course also sign them yourself, no ca is needed besides for the ssl server cert. most of the points on that site is moot besides poor support on some browsers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: