Basically, the site would have a copy of my public key (say my GPG key or an ssh key), and to authenticate I prove that I have access to the corresponding private key.
Basically, the site would have a copy of my public key (say my GPG key or an ssh key), and to authenticate I prove that I have access to the corresponding private key.
There's an addon for Firefox called Enigform (I've not tried it out yet) which uses PGP for web authentication:
But the worse GUI is arguably better than no GUI at all:
http://code.google.com/p/android/issues/detail?id=8196 and http://stackoverflow.com/questions/357491/iphone-client-cert...
So, for the purposes of the growing mobile browser market (where having this would be the biggest benefit IMO), this is not applicable.
Which is a bit unfortunate.
http://googleblog.blogspot.com/2011/02/advanced-sign-in-secu...
yet my bank's web site, not so much.
What I was talking about was something different. Public/private key encryption where only the public key is stored on the server.
Here's an example scenario: the server generates a random pass-phrase then encrypts it using the public key. The end-user then uses their smartphone where the private key is stored to decrypt the message and return the original pass-phrase back to the server, proving they have the private key. There are similar ways of achieving a similar result that are less cumbersome and awkward. The advantage is that if the public key is leaked it's not a big deal, it can't be used to gain access to the system.
What do you do when you loose the keys?
You don't. And ideally you have a single key. If you can be trusted to keep a social security card and a passport, you can just as easily keep a key safe. Print it out. Store it in a safe place. We've been doing that for centuries. And the default behavior or enabling keys whenever your computer is open?
You can password protect your keys.If someone steals your passport, you'll know: you won't be able to find it.
Digital keys have no such properties. If someone steals your private key, you will have no idea until you see them steal all your money and accounts.
Physical items also need to be carried to a destination to be used. If someone steals your passport, they may be able to take over your bank accounts, etc. For that, they have to actually go in person to meet a bank manager and pretend to be you. People do that fairly successfully, but it's hardly an efficient process.
A digital passport/key, on the other hand, could be abused immediately after it's been stolen, and could be used across all your accounts within the hour, before you've even realised you've been robbed.
Finally, you can only use one passport at a time. Not only it takes time, but you need a career criminal dedicated to each "process".
A digital key robbery, however, requires no human element, and thus can be done in parallel at a large scale. One could use Trojans to capture the keys of a large number of people and steal their money in an automated manner without ever showing up at a bank.
All those problems can perhaps be solved, but they are not easy and they have nothing to do with keeping the key safe - more to do with keeping the process of using the key as inefficient as possible. The best way to ensure your digital key cannot be abused is to make sure that you can only use it in person in front of other human beings, on authorised hardware.
So, pretty much like the way our bank cards work, then.
In a couple of years everyone will have on of those cards, the problem is that nobody has readers.
1. http://www.independent.co.uk/news/uk/home-news/clone-wars-mo...
2. http://www.expatsvoice.org/forum/showthread.php?t=7001
I guess that Mossad can gather the information needed to clone a passport in under half a minute.
So while I agree that the analogy between key reminder and password is not perfect, the point is basically sound.
(On rereading your post, your point [p]hysical items also need to be carried to a destination to be used made me realise that I might have misunderstood the point you were making, but also that you may have misunderstood the point ihodes was making).