can someone please create secure and user friendly mTLS implementations for everything (password managers, systems, web servers, etc)?it turns out that those who make passkeys are massive retards and those who make the standard have no idea what they're doing as proven by the increasing amount of proprietary passkeys implementations that will not even succeed in replacing passwords+totp, this joke needs to end very fast
>>109677011
Doesn't mTLS rely on in-band signalling? Wouldn't any TLS terminating revproxy break it?
>>109677011passkeys just move the leak responsibility from the server to the client, which is neat, it doesnt really do anything else
>>109677193That wouldn't be a bug, but a feature.Running Auth through a MitM like Cloudflare would defeat its whole purpose
>>109677218Ya but... Ok, hear me out, what if you have a load balancer (that you own and trust) and a bunch of webapp instances behind it? Would you architect the auth to happen in the loadbalancer or what? This is already a problem I see people fuck up with Kerberos and GSSAPI and forget what an SPN is.
>>109677226Oh and ya, we already have kerberos. Lets me make that great again or something too. Anything is better than retarded ass passkeys.
>>109677011you forgot to ask us not to make any mistakes