<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE rss [<!ENTITY % HTMLlat1 PUBLIC "-//W3C//ENTITIES Latin 1 for XHTML//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml-lat1.ent">]>
<rss version="2.0" xml:base="http://www.kai-mai.com">
<channel>
 <title>Kai Mai&#039;s Blog - Take Back the Web - Nodes for openid</title>
 <link>http://www.kai-mai.com/tags/openid</link>
 <description>Nodes containing the tag openid</description>
 <language>en</language>
<item>
 <title>Love OpenID, Hate Password?  Get Your Password-less SSL Certificated OpenID From Certifi.ca</title>
 <link>http://www.kai-mai.com/node/123</link>
 <description>&lt;p&gt;
Slowly, more and more sites have supported login using &lt;a href=&quot;http://en.wikipedia.org/wiki/OpenID&quot;&gt;OpenID&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
The selling point of OpenID is that you can use one login to access varies sites.  This is very convenient.  But I am worried about losing the same passwords for all the OpenID supported sites I access.  There are so many &lt;a href=&quot;http://en.wikipedia.org/wiki/Phishing&quot;&gt;phishing&lt;/a&gt; activities going on to steal passwords.  I need something that&#039;s not password-based.
&lt;/p&gt;
&lt;p&gt;
I came across &lt;a href=&quot;https://certifi.ca&quot;&gt;Certifi.ca&lt;/a&gt; which is a password-less OpenID provider using SSL certificate for &lt;a href=&quot;http://en.wikipedia.org/wiki/Public-key_cryptography)&quot;&gt;public key-based&lt;/a&gt; authentication.  The basic idea is that you store your public SSL certificate(public key) and the private key in your browser.     Certifi.ca identifies you by your public key, and uses your public key to encrypt communication  between your browser and itself.  Your browser with the private key is the only one that can decrypt the communication.  There&#039;s no password needed!
&lt;/p&gt;
&lt;p class=&quot;awTags_TagLinks&quot;&gt;Tags: &lt;a href=&quot;tags/192&quot;&gt;ssl&lt;/a&gt; &lt;a href=&quot;tags/193&quot;&gt;certificate&lt;/a&gt; &lt;a href=&quot;tags/194&quot;&gt;public&lt;/a&gt; &lt;a href=&quot;tags/195&quot;&gt;key&lt;/a&gt; &lt;a href=&quot;tags/196&quot;&gt;openid&lt;/a&gt; &lt;a href=&quot;tags/197&quot;&gt;provider&lt;/a&gt; &lt;a href=&quot;tags/198&quot;&gt;certifi.ca&lt;/a&gt; &lt;a href=&quot;tags/200&quot;&gt;cacert.org&lt;/a&gt; &lt;/p&gt;</description>
 <category domain="http://www.technorati.com/tag">ssl</category>
 <category domain="http://www.technorati.com/tag">certificate</category>
 <category domain="http://www.technorati.com/tag">public</category>
 <category domain="http://www.technorati.com/tag">key</category>
 <category domain="http://www.technorati.com/tag">openid</category>
 <category domain="http://www.technorati.com/tag">provider</category>
 <category domain="http://www.technorati.com/tag">certifi.ca</category>
 <category domain="http://www.technorati.com/tag">cacert.org</category>
 <pubDate>Tue, 25 Dec 2007 17:21:36 -0800</pubDate>
</item>
</channel>
</rss>
