I'll keep you posted on progress, if your email is in your profile. Hoping to have everything (plug-in and serverside examples) ready in a week or two.
I'll keep you posted on progress, if your email is in your profile. Hoping to have everything (plug-in and serverside examples) ready in a week or two.
If you were to use WebCrypto, it ought to be possible to securely (with respect to cross-origin policy) store a user's private key using IndexedDB.
WebCrypto has support for keypairs that can have the private key data extracted (there are limits, though, which I cannot accurately remember) from the JavaScript object in which they are contained.
So it ought to be possible to extract the key data, encrypt it (also using WebCrypto) and sync it (somehow) to another device.
Add key for <user@website> at <utcmillisecs>: <new_public_key_goes_here>;<sign>
Again, having a command ("Add key ..." as in parent message) for this would make this feature accessible to password/key managers.
I love the idea. It reminds me of something I read on HN a few years back where somebody proposed using SSH auth for web authentication.