User authentication approaches
Drew DeVault
sir at cmpwn.com
Thu Nov 19 16:22:41 GMT 2020
On Thu Nov 19, 2020 at 11:21 AM EST, Steve Lord wrote:
> I was wondering how/if people are handling user authentication? I
> recognise that certificates could probably work, but these would
> authenticate a device rather than person. If the person loses the cert I
> imagine recovery would be difficult.
I think we should normalize having to take care of your certificates,
and user agents should provide easy tools for doing so. Certs are much
better than, say, username & password.
If it becomes a problem in practice, perhaps we could do something like
handling certificate resets over email, similar to password resets are
done on the web.
Or you could just get in touch with the owner of the capsule if you get
locked out. Gemini is small and the human touch is still there, and I'll
be happy if we can hold the cold, unfeeling machine-governed
interactions at bay for a bit longer.
More information about the Gemini
mailing list