W3C home > Mailing lists > Public > public-webappsec@w3.org > March 2016

Re: Alternative proposal for the form signing using client-certificate

From: Mitar <mmitar@gmail.com>
Date: Thu, 10 Mar 2016 01:15:32 -0800
Message-ID: <CAKLmikPRMdetE-iVN5JRC_qHQkWq+Li15Jz83crwdPg28VsgLQ@mail.gmail.com>
To: Anders Rundgren <anders.rundgren.net@gmail.com>
Cc: Crispin Cowan <crispin@microsoft.com>, "timeless@gmail.com" <timeless@gmail.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>
Hi!

On Wed, Mar 9, 2016 at 2:46 AM, Anders Rundgren
<anders.rundgren.net@gmail.com> wrote:
> - the other browser vendors are publicly considering dropping support for
> <keygen>

In fact I do not care so much about key generation in the browser. I
just hope they allow importing a certificate into a keystore, or
access to system's keystore.

> - smart cards have never worked particularly well in consumer computers

Depending who you ask. In Europe there are countries (like Estonia)
where they work pretty well and many people vote online.

https://e-estonia.com/component/electronic-id-card/

Similarly in Slovenia there are state-issued certificates one can use
to work with government online.

> - practically all eID schemes have already take on other ways dealing with the Web

Yes, currently they use custom extension to make it work, if this is
what you mean "other ways". They use other non-standard ways to make
it work. What I would like to find is a standard way to make it work.

https://github.com/open-eid

How much software instead of one simple HTML form element?

BTW, I asked already before, can somebody point me to those "other
ways" which really can replace eID schemes in the way that: you get a
3rd party verifiable statements, and that they are legal bounding in
the same way eID schemes are currently in countries in Europe? I have
not found any legal changes around that. So those claims have not yet
been supported.

What I see is that currently laws in Europe provide untapped
opportunities which cannot be build upon mostly because there is no
simple support for them in browsers. It really feels that this is just
because it is not known much in USA?


Mitar

-- 
http://mitar.tnode.com/
https://twitter.com/mitar_m
Received on Thursday, 10 March 2016 09:16:01 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:18 UTC