Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"LetsEncryptEmail" sounds like a good idea. It seems like there would be lessons to learn from Mozilla's Persona / BrowserID project which followed similar goals at a technical level. For instance, in addition to falling back to OTP codes sent to an email address for verification, they had a reasonably smart idea that you could use OIDC ("OpenID Connect") to validate logins more directly to at least major email providers like Gmail and Yahoo since many of the majors do have an OIDC endpoint or two.

(Mozilla Persona was a great project idea and a shame it never got enough market share. It didn't end up using personal certificates, though IIRC they explored that as an option and what they did use was technically very close.)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: