@ISometimesAdmin@the.coolest.zone avatar

ISometimesAdmin

@ISometimesAdmin@the.coolest.zone

I sometimes admin. But usually not.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

To separate Email address from being an online identity, a concept I thought up, detailed by ChatGPT,

Hello Privacy Subscribers of Lemmy, I’m Webhost0101. With the help of ChatGPT, I’ve been exploring the challenges we face with digital identity, particularly regarding the use of email addresses. I’ve developed a concept aimed at enhancing privacy and security in our digital interactions....

ISometimesAdmin,
@ISometimesAdmin@the.coolest.zone avatar

Others beat me to the punch on saying this is just worse WebAuthN, but there are some specific flaws that boil down to saying that this whole thing is, at best, totally inconsiderate of real attack vectors such as phishing

Online Login: On supported platforms, log in with your ‘Sign’ rather than your email address. The service checks for a corresponding email in their database that produces the same hash with the chosen algorithm/options. Services can eventually replace emails with ‘Signs’ for regular users.

Enhanced Privacy: Limits the need to share email addresses, reducing spam and data breach risks.

Huh? What does this even mean? How can you avoid sharing your email and replace it with a sign, if they need to check it against their database of... Emails?

Real-Life Usage: In physical stores, use your QR-art ‘Sign’ when asked if you have an account/booked at table.

Ah excellent. Someone can just look at a security camera or just snap a photo over your shoulder and steal your sign then. Because your proposal sure doesn't note any way that these are 1-time use only. And if they were, this sounds like an awfully inconvenient way of receiving a temporary number (which sites usually only ever do as a cheap/bad 2FA method/password resets)

Email Verification: Receive a unique link via email, confirming your email’s validity.

Oh boy, better make sure to not get phished! Or that the link is 1 time use! Or that you aren't being victimized by a MITM attack and getting it intercepted immediately!

ISometimesAdmin,
@ISometimesAdmin@the.coolest.zone avatar

Yeah, considering how in-your-face this popup was, I can't really take someone seriously when they just say that it was "opt-out"...

Like, I get it on a technicality. But c'mon.

ISometimesAdmin,
@ISometimesAdmin@the.coolest.zone avatar

That's only for a single service, not really what OP seems to be asking for

Everybody is supporting Firefox, but no one wants to use it. Because it is destroying itself. (discuss.tchncs.de)

Mozilla’s stable browser is not stable enough. especially the Android-based one. They are destroying that amazing browser with every single update. Mozilla converted Firefox from a great-promising browser to a crappy, useless browser. Don’t you think so?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #