Why couldn't Public keys replace Passwords on the Internet?

From: Dave (galt_57@hotmail.com)
Date: 01/24/03


From: galt_57@hotmail.com (Dave)
Date: 24 Jan 2003 06:30:50 -0800

What if you just used a challenge and response system to replace
passwords? The browser could hold the users password which would
generate his private key. Websites would be allowed to challenge with
a date-time-magic-cookie-root-web-address using your public key. Your
browser would then prompt you to see if it should respond to prove
your identity.
 
Advantage: you would just log into your browser. Only one password to
remember. Also no passwords would be passed across the internet. The
root-address check would eliminate fake webpaages and the date-time
field would obsolete any visible data.

Dave



Relevant Pages

  • Re: Remember Password - does Not after shutdown
    ... What is the browser that exhibits this problem? ... Download, install, update and do a full scan with these free malware ... password information has been compromised and then use the tools built ... Then the user names and passwords will all have to be ...
    (microsoft.public.windowsxp.general)
  • Why couldnt Public keys replace Passwords on the Internet?
    ... The browser could hold the users password which would ... generate his private key. ... Websites would be allowed to challenge with ... Also no passwords would be passed across the internet. ...
    (microsoft.public.win2000.security)
  • Re: Sites and Services
    ... The changing of the passwords and browsing are probably separate. ... The reason you can't see the machines is because there isn't a master ... the domain -basically you have one master browser per site, ... The PDCE, by default, is the domain master browser. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Firefox security question
    ... pull sensitive information off of your system via the browser. ... network.http.sendSecureXSiteReferrer user set boolean false ... Security numbers, or passwords for stuff like online banking etc. it's ...
    (comp.os.linux.security)
  • Access a .onion URL without tor
    ... You cant do in your browser, but now you can if you use this: ... They're easily obtainable and will remove the passwords ... They are under enough pressure as it is given me headaches for posting, ...
    (alt.privacy)