Login in one browser, go to Preferences->Pairing, click the button and you get a PIN. Next you can just copy/paste the PIN into a different browser and it will authenticate you as if you were using your WebID. -- cc timbl
This is huge, since you can now login to MP on your mobile phone without using WebID-TLS.
can you login to melvster's calendar... http://calendar.data.fm/index.html ?
oops you would have to https:// that link
...I don't get the part about Mobile
...I always want TLS on my phone
not all phones support TLS authentication
browsers don't have access to the certs :(
its true, once desktop browsers are conformant we can worry about mobile :)
but I dont want to use a phone without TLS or some other crypto with the linked data at my bank
hmm, the calendar is stuck at "Loading user..."
the pairing PIN is only valid for 1 minute
and MP forces HTTPS all the time
pairing -- great
timbl, I've also added account recovery (uses private emails -- not visible on the profile page)
stronger auth should be an option too, eg. 2-factor
presbrey, that's something I'm considering too
multi-factor rather, popping up on all the major social networks recently
well, WebID is pretty robust from that point of view
Beware of SSL man in the middle attacks
by one's employer or state
I'm not sure how one can protected himself against that
note HSTS has helped against a few MITM attacks