Let's hope this doesn't get picked up by the (corporate) masses... the last thing I want is my browser offering personal TLS certificates to every server I visit as some kind of identity verification or fingerprint/tracking.
It's bad enough that ssh does this by default with all your keys.
Client TLS is rather unusable on the Internet by a typical random end user visiting a random public site, so that should at least keep the specific scenario you describe at bay.
Sounds interesting; too bad all we get is text made up by an LLM rather than any of the author's insights.
Yeah I was interested for the first few paragraphs, then all of a sudden I get hit with two "genuinely"s and a
> That’s the third property, and it’s the one that decides this.
and I gave up at that point.
Nothing new here, attested TLS was being discussed in IETF for quiet sometime right?
https://datatracker.ietf.org/doc/draft-fossati-tls-attestati... https://www.youtube.com/watch?v=MF9AwkMJOlw
Let's hope this doesn't get picked up by the (corporate) masses... the last thing I want is my browser offering personal TLS certificates to every server I visit as some kind of identity verification or fingerprint/tracking.
It's bad enough that ssh does this by default with all your keys.
Client TLS is rather unusable on the Internet by a typical random end user visiting a random public site, so that should at least keep the specific scenario you describe at bay.