zlacker

[return to "Apple already shipped attestation on the web, and we barely noticed"]
1. toyg+Za[view] [source] 2023-07-25 14:54:02
>>pimter+(OP)
This might be where the internet really gets forked, as it's been predicted over and over since the '90s.

On one side, we'll have a "clean", authority-sanctioned "corpweb", where everyone is ID'ed to the wazoo; on the other, a more casual "greynet" galaxy of porn and decentralized communities will likely emerge, once all tinkerers get pushed out of corpnet. It could be an interesting opportunity to reboot a few long-lost dreams.

◧◩
2. TheNew+Ki[view] [source] 2023-07-25 15:22:17
>>toyg+Za
The problem I have with this web attestation concept generally is that I really want it _inside_ my shiny SSO-everywhere-Zero-Trust-at-the-edge-mTLS-everywhere business network.

I also kind of want it in the public-cloud-meets-private-use home environment (that is, my Cloudflare Access tunnels and MS365 business tenant I use for private stuff).

I don’t want it to touch my personal browsing experience or in any way involved in my personal-use browser environments.

These are effectively opposed desires at this point, and it’s a cat-out-of-the-bag technology.

◧◩◪
3. Mayeul+Nk[view] [source] 2023-07-25 15:31:16
>>TheNew+Ki
Are you sure you don't just want client certs?

I can also imagine an IPv7 with ephemeral addresses based on private keys (like on yggdrasil), and a way for the browser to remember keys if wanted by the user. Authenticate sessions with the "IP address".

[go to top]