Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Yeah, none of big tech wants that, they don't want to make it easy for 3rd party.

Ideally there would just be standarized interface between "credential manager" and applications + some OS-enforced security (so password manager knows which PID sent the question about password or other type of credential).

Then we could have say pub/privkey or cert based authentication implemented there, app just asks for a credential for a site and cred manager asks user whether to allow it once or forever, and which credential to give.

The app then could garnish that with extra metadata so say firefox container feature, or different firefox profile could attach metadata about from which container or profile the request comes from, and credential manager could hand out different credentials based on from where it came.



> Yeah, none of big tech wants that, they don't want to make it easy for 3rd party.

iOS has an API for password managers and HOTP/TOTP authenticators. Android is planning to introduce one for passkeys.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: