|
-
October 6th, 2005, 10:12 PM
#20
Trouble is any idiot can get a digital cert for a few $ saying they are just about anyone they like.
To get identity confirmed digital certs costs loads more and would preclude lots of members of this site.
Reread what I said... the dig cert would just be used to allow registration beyond a few newbie forums. And if some user wants to throw money away so that they can be annoing and get themselves banned... well, at leas they have to pay for it.
I agree the process of utilizing Digital IDs for registration is simple. It's the primary and preferred method of authentication inside my employers network for web resources, and it's simple and slick.
I'm commenting on the backend processes of having proper, approved, supported Digital IDs in use by everyone. What CA (or CA's) are trusted for this purpose. What type of certificates are allowed? Who supports certificate issues. What if a legitimate security pro comes from a company that uses an alternate method? Et cetera ad naseum.
You're over thinking the issue, it doesn't need to be secure... it merely needs to increase the effort required for someone to make multiple, non-matchable accounts.
It doesn't need to be a proper dig cert processing system... it could even accept personal/expired certs... but doing so would dramatically up the amount of effort required for someone just looking to troll.
Again though this isn't justified by the ROSI.
cheers,
catch
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|