2017-05-31 UTC
# saranix hmm. Yeah, remote auth seems to be a 'solved' problem, there is no shortage of sensible solutions. The problem is more with *local* auth, i.e. the software (website) that is hosting the identity confirming the browser in question is the one that owns that account [typically done with passwords, better with TLS client certs]