Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

HTTP basic auth, TLS with client certs.


Those things don't do what OIDC does?


They do them with much less complexity than OIDC.


They absolutely do not and also introduce a significant amount of overhead with respect to key/certificate management.


And security (basic auth is as good as sending clear text passwords).


> sending clear text passwords

Which is totally fine to do over HTTPS.


Passwords need to be sent both with the request, and to the requestor. I think GP is referring to sending credentials to the service making the request.

It is far better to give service XYZ a time-bound and scope limited token to perform a request than a user's username and password.


Isn't Google moving toward phasing out TLS client certs in chrome/chromium?


Do you have any source for that? I can't find anything online about this, but that would effectively kill browser mTLS.


Chromium removed support for generating TLS Client Certs within chrome in 2016 [0] and ever since then it has gotten harder and harder to use mTLS in Chrome/Chromium. Ten years ago it wasn't a great UX, but now it isn't even obvious how to use it. The impression I've gotten is that Chrome isn't interested mTLS.

[0]: https://groups.google.com/a/chromium.org/g/blink-dev/c/z_qEp...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: