Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't follow you, what's invasive/interfering about it? You & your browser can decide whether any of the steps of this process actually happen.


The proposed BrowserID standard specifically suggests that the browser should ask the email provider to validate the email, and only fall back to the usual email-me-a-link validation if the email provider doesn't "natively" support BrowserID. I'd prefer to always go through email-me-a-link verification (ideally with some kind of crypto involved), rather than involving the email provider in any way other than SMTP and IMAP.


Can you link me to where you're reading that? I don't see anything like that (but I've only skimmed the documentation).


See the teaser at https://browserid.org/primaries , and the documentation at http://lloyd.io/how-browserid-works .


I've read it more thoroughly now, but I'm still not sure where you're coming from. You'd rather use a secondary identity authority, even when a primary is available? Or are you saying you'd like to require a full send-me-an-email-and-i'll-click-on-a-link verification every time you log in to a relying party?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: