Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My developer self loves this idea, knowing that my secret key doesn't even leave the computer.

My traveler self hates the idea, because I can't read my emails from my friend's phone when my phone is broken during our 6 month trek.



My security self hates this idea, because a single point of failure is not a good design. How would the key be revoked if lost? Replaced? This seems to necessitate a CA-type infrastructure (like TLS certs). Not something I'm comfortable trusting any corporation or government with.


If the account is that important to your life, then there are probably other identifying information associated with it, credit card numbers, addresses, etc. Do what you do today when identities are stolen: contact the company, prove you are who you say you are, and the'll let you assign a new key to your profile.

Otherwise, who cares? Gen a new key and get on with life.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: