Re: The real problem that https has conspicuously failed to fix

daemon@ATHENA.MIT.EDU (Nomen Nescio)
Thu Jun 12 10:24:16 2003

X-Original-To: cryptography@metzdowd.com
From: Nomen Nescio <nobody@dizum.com>
To: jis@mit.edu, cryptography@metzdowd.com
Date: Thu, 12 Jun 2003 10:50:10 +0200 (CEST)

Jeffrey I. Schiller writes:

> Oh, and btw, the form posting URL in my message wasn't even https, it 
> was just http. So all the futzing in the world with https wouldn't help!

Of course it would help.  Have you been following this discussion
at all?  The idea is to eliminate passwords as being of any value in
getting access to PayPal or other ecommerce sites, by replacing them
with client certificates.  This implies using https or something
cryptographically similar.

