Origin-bond keys - A different view

FWIW I don't agree with these conclusions:

http://lists.w3.org/Archives/Public/public-webcrypto/2012Aug/0059.html

Key Reuse:
Keys that are given to you by a service (regardless of how) are owned by the service.
This is valid for credit cards and I think it translates to most other services as well.
You are not supposed to use such keys for any other purpose than they were issued for.

Key Lock-in:
A key doesn't "Lock-in" more than any other persistent data.
If you don't like the service, don't use it.

Key Migration:
Users do not [generally] know what a cryptographic key is and I don't think they should ever need to either.
There's no UI in the world that can fix that.

Expired but Related I-D:
http://tools.ietf.org/html/draft-balfanz-tls-obc-01

Anders

Received on Friday, 10 August 2012 05:10:30 UTC