Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Many tens of millions of people log into web applications every day, and you are proposing that they all somehow be issued PKI certificates and USB fobs, and that that be the primary way they get access to their data.

You should talk to someone who manages fob deployments at a Fortune 500 company. These are environments supporting hundreds or thousands of users, not millions, and virtually all those users are highly paid, not fixed-income retirees. In particular, ask them about how easy it is to handle lost, damaged, and stolen fobs.

Clearly, we weren't going to standardize on everyone getting a certificate on a USB key --- even had USB keys actually been feasible 15 years ago.



The Department of Defense uses smart cards with X.509 certificates. I am not aware of all the details of this deployment, but I think they have millions of users.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: