Re: [dix] Re: [Ietf-http-auth] BOF Request: WARP - Web Authentication Resistant to Phishing
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [dix] Re: [Ietf-http-auth] BOF Request: WARP - Web Authentication Resistant to Phishing
Sam Hartman <hartmans-ietf at mit.edu> writes:
>>>>>> "Eric" == Eric Rescorla <ekr at networkresonance.com> writes:
>
> Eric> Sam Hartman <hartmans-ietf at mit.edu> writes:
> >> Yes, your understanding is correct.
>
> Eric> Good. Then we have a basis to talk about them.
>
> I basically agree with the general statements you have made. I
> believe that the specific example of age verification on the web will
> tend not to fall into the case where people use independently asserted
> idenity claims especially in the medium future. I don't have high
> confidence in that belief though and I don't think it matters much
> whether I'm right or not. We both agree that there will be third
> party claims.
>
> As I've said before I think that whatever we design needs to
> eventually support claims and third party claims.
I think there's a missing part to this statement: if you plan to
support third party claims, I think there's a pretty strong argument
that such claims need to be independently assertable.
-Ekr
_______________________________________________
dix mailing list
dix at ietf.org
https://www1.ietf.org/mailman/listinfo/dix
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.