nanog mailing list archives

Re: LinkedIn password database compromised


From: Randy Bush <randy () psg com>
Date: Thu, 21 Jun 2012 08:02:58 +0900

leo,

what is the real difference between my having holding the private half
of an asymmetric key and my holding a good passphrase for some site?
that the passphrase is symmetric?

First time a user goes to sign up on a web page, the browser should
detect it wants a key uploaded and do a simple wizard.
  - Would you like to create an online identity for logging into web
    sites?    Yes, No, Import

s/onto web sites/this web site/  let's not make cross-site tracking any
easier than it is today.

randy


Current thread: