Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] how do you 'web password' ?



>>>>> "Evan" == Evan Monroig <evan.monroig@example.com> writes:

    Evan> Since we use public/private cryptography for signing emails,
    Evan> or authentication to remote servers with ssh, why not use it
    Evan> for the dozens of accounts that we use on the web?

I don't see the use case for myself.  True, I have a couple dozen
Bugzilla accounts, but I use the same password for all of them.  If
that's good enough for the Bugzilla operators, it's good enough for
me.

As for why bank accounts and Paypal etc don't, I have to assume it's
because Windows as normally set up and used cannot do anything
securely (spyware), so the best you can do is secure the channel with
SSL or TLS to protect against men in the middle, and use passwords to
make it somewhat difficult to break in if the attacker doesn't have
access to the machine.


-- 
School of Systems and Information Engineering http://turnbull.sk.tsukuba.ac.jp
University of Tsukuba                    Tennodai 1-1-1 Tsukuba 305-8573 JAPAN
               Ask not how you can "do" free software business;
              ask what your business can "do for" free software.


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links