Re: Smart Card and WebCrypto (Re: On the future of <keygen> and application/x-x509-*-cert MIME handling)

Joseph Lorenzo Hall <[email protected]>
Newsgroups gmane.comp.mozilla.devel.platform,gmane.comp.mozilla.security
Message-ID <CABtrr-XuXss8Tv97jVH2tJp2kDPkj1qy-4Np0eVVswVZ5swu5A@mail.gmail.com>
On Sun, Aug 30, 2015 at 1:50 AM, Anne van Kesteren <annevk-6shE6wEKUUpmR6Xm/[email protected]> wrote:
> On Sun, Aug 30, 2015 at 7:33 AM, Tim Guan-tin Chien
> <[email protected]> wrote:
>> It's also worthy to point out many nation-state deploys Smart Card
>> identifications (despite the privacy concern), allow it's citizens (or
>> subjects) to authenticate with government services online.
>
> It seems a potential future for that which works within the web's
> security model is FIDO, see
>
>   https://fidoalliance.org/
>   https://support.google.com/accounts/topic/6103521
>
> I don't think we're currently working on this though.

(from the inveterate lurker...)

I've said this to a number of FF folks but it would be great to get
FIDO U2F support in FF; the U2F-enabled yubikeys/harware tokens etc.
are a great, usable 2-factor technology, but it's hard to recommend
people use them when they only work in Chrome. :/

best, Joe

-- 
Joseph Lorenzo Hall
Chief Technologist
Center for Democracy & Technology
1634 I ST NW STE 1100
Washington DC 20006-4011
(p) 202-407-8825
(f) 202-637-0968
[email protected]
PGP: https://josephhall.org/gpg-key
fingerprint: 3CA2 8D7B 9F6D DBD3 4B10  1607 5F86 6987 40A9 A871
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.