On 6/26/23 5:51 AM, Phillip
Hallam-Baker wrote:
I spent the
weekend bringing up a new PC and the experience demonstrated
many weaknesses in the current authentication infrastructure
and the near complete lack of user autonomy. I have no
choice but to use an OAUTH account to log in to many
applications etc. and the user experience is dire. I ended
up responding to at least a dozen PIN challenges to my
mobile device. My environment is somewhat extensive but it
really isn't that much more complex than a regular user's.
IETF has
traditionally avoided doing UI but in this case, the UI is
the protocol and it is impossible to discuss the security of
the system without discussing the boundaries between what
the user can and cannot trust.
Yeah, IETF is a very strange venue for something like OAUTH. Why
wasn't it done at W3C? At least they do UI stuff, and more to the
point have better clue of the inner workings of browsers. It would
have also driven home the point that it was a web thing, not a
general thing.