| ▲ | ranger_danger 4 hours ago |
| Let's hope this doesn't get picked up by the (corporate) masses... the last thing I want is my browser offering personal TLS certificates to every server I visit as some kind of identity verification or fingerprint/tracking. It's bad enough that ssh does this by default with all your keys. |
|
| ▲ | zx8080 2 hours ago | parent | next [-] |
| This is most probably where it's going in less than a year. The recent campaign "Safer with Google" in Chrome hints to this. |
|
| ▲ | altairprime 2 hours ago | parent | prev | next [-] |
| Client TLS is rather unusable on the Internet by a typical random end user visiting a random public site, so that should at least keep the specific scenario you describe at bay. |
| |
| ▲ | ranger_danger 2 hours ago | parent [-] | | Currently yes, but there's not much stopping Chrome etc. from adding a new feature that has a way of presenting a client certificate to a website in a backwards-compatible manner. Of course the website itself would need to support that, but it's all possible in time. | | |
| ▲ | altairprime 2 hours ago | parent [-] | | Chrome would be more likely to implement a persistent and identifiable (to Google alone) tracking cookie replacement and ship it worldwide, which iirc they did — and then cancelled, of course. They seem to be focusing instead on improved tracking of Android users from the kernel up, rather than browsers from the headers down; GrapheneOS is, presumably, viewed as a serious threat to their advertising revenue. https://privacysandbox.google.com/blog/update-on-plans-for-p... |
|
|
|
| ▲ | bschaatsbergen 2 hours ago | parent | prev [-] |
| [dead] |