Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You don't show your ID to a TTP you show a homomorphic function of your ID which doesn't leak your credentials and you have a second homomorphic function in the website to the TTP which doesn't leak what your verifying against.

2 and 3 are correct but 1 isn't. They don't get to hold reusable credentials about you, only a function in them which can be verified to show you hold the identity.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: