Why is nobody using SSL client certificates?
11–20 of 160 posts
Re: Why is nobody using SSL client certificates?
#12The key management tools are awful. People complain about the complexity of PGP but at least there it's one-click to export a key, look at the details of it, sign someone else's key etc. But yeah, it would be nice to use this tech rather than reinventing the wheel. The underlying implementation is sound.
The whole system, now close to 20 years old, needs a reboot. I know, that's easy for me to say. But it's showing its age, and could really benefit from a complete rethink.
Re: Why is nobody using SSL client certificates?
#13I'd love to see browsers implement it by forcing people to store client certs on a USB-key or a phone by default. I think some kind of physical item that contains your keychain would be much more intuitive to many. Everyone is familiar with mechanical keys, they know not to leave them around, they know that they need them to unlock things and they know if they lose them they need to replace them.
Re: Why is nobody using SSL client certificates?
#14I have a password on my phone, because I don't want people with access to it to be able to login and look at my stuff. What's to stop my friend Joe Blogs coming over my house and being able to read my email because I have one of these things installed that allows for a one-click login?
Re: Why is nobody using SSL client certificates?
#15If 50% of my traffic already tried offering me a client cert the decision to allow them would be an easy one to make.
Re: Why is nobody using SSL client certificates?
#16Client certificates should be much more popular in backend applications, where they're straightforward to use, flexible, and fairly trustworthy. But they're not a good end-user technology.
Re: Why is nobody using SSL client certificates?
#17Yep -- too hard to setup. A really good browser enhancement would be 1-click client side certificate setup.
Re: Why is nobody using SSL client certificates?
#18Re: Why is nobody using SSL client certificates?
#19Re: Why is nobody using SSL client certificates?
#20The whole DOD is using it, but they're on crypto smart cards, so many folks don't realize that's what they're doing. Email, single sign on, web site auth, etc. Works great!