Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Expecting unique client machine/network profiles for each seller account seems fundamentally incompatible with a web-based access model. Then again, maybe it's merely incompatible with a Good web-based access model.

Modest proposal: Distribute smart cards and readers to sellers, and use mutual-auth TLS for everything. Or offer this as an option to anyone willing to pay $xxx for their initial sign-up fee.



> Distribute smart cards and readers to sellers

Jeebus, this makes too much sense.

If Blizzard can hand out OTP generators for it's users, surely Amazon or retailers can do the same for it's sellers.

Hell, look to Google and their Authenticator app or SMS-based 2-step login (out of band auth channel would be better).




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: