Re: Smart Card and WebCrypto (Re: On the future of <keygen> and application/x-x509-*-cert MIME handling)

Anne van Kesteren <[email protected]>
Newsgroups gmane.comp.mozilla.security,gmane.comp.mozilla.devel.platform
Message-ID <CADnb78iqYkFYAmB7XRCN59X6dACTK_tMk2hZamDJY8NZRBNtdQ@mail.gmail.com>
On Sun, Aug 30, 2015 at 11:37 AM, Tim Guan-tin Chien
<[email protected]> wrote:
> Indeed, banks in Taiwan are slowly rolling out OTA based
> authentications primary mobile app banking users, despite 100% of the
> ATM cards are already smart cards (required by legal mandate against
> forgery since 2006) and you can already access back accounts from
> "WebATM" websites & smart card readers with -- again, ActiveX or Java
> plug-in.
>
> I can't argue if either is securer or "better" compare to another, but
> it's important to acknowledge we cannot change the banking industry or
> government IT service industry over night by refusing providing
> solutions.

Well, if they're using ActiveX or Java (both seem rather terrible from
a security perspective, but okay), it seems they're not using <keygen>
either, so that solution was probably not sufficient either way.

I agree there needs to be a solution of sorts, but it might take a
while until we figure something out that works for the web and world
at large.


-- 
https://annevankesteren.nl/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.