| ▲ | alentodorov 9 hours ago | |||||||||||||
Apple Wallet passes use CMS signatures. you're right that only hashes are signed. but Apple requires an official Developer certificate ($99/year) with a private key that can't be exposed to browsers. for true privacy, each user would need their own cert. and defeats the "free" goal. and if you have a dev certificate it's trivial to generate one on your own machine. | ||||||||||||||
| ▲ | gruez 9 hours ago | parent | next [-] | |||||||||||||
>Apple Wallet passes use CMS signatures. you're right that only hashes are signed. but Apple requires an official Developer certificate ($99/year) with a private key that can't be exposed to browsers. Why can't the browser send the hash to the server for signing? | ||||||||||||||
| ||||||||||||||
| ▲ | saagarjha 9 hours ago | parent | prev [-] | |||||||||||||
Any chance of allowing me to upload my own keys and doing the signing in the browser? I am sure this is a niche use case but I know how to generate the certificate for this but have been too lazy to make a thing like this for (checks to-do list) something like six years and I'd much rather just use your thing lol | ||||||||||||||
| ||||||||||||||