Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> You can see where this is heading—a half-baked reimplementation of TLS client authentication with all the same usability nightmares.

Yeah, that's what I was thinking -- why would you do this instead of just using TLS client auth? TLS client auth is a usability nightmare -- but I'm not sure it's any _worse_ than what's in OP.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: