Because the tech for sites to provision bearer tokens exists, but the tech for sites to provision client certificates doesn't. It's a much smaller lift to just have client systems handle certificate generation than it is to get cross-browser support for a mechanism for services to grant a certificate to the client.
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
no subject
Date: 2022-05-18 08:50 pm (UTC)