Easy. Tell your partner to kiss off. You work 40hrs a week. You won't get more than 40 hrs of productivity out of a week. So what's the point in destroying your health and interest in the project by putting in more hours?
HN user
swadworth
Who said MITM isn't a threat? I'm talking about the difference between targeted surveillance (MITM) and dragnet surveillance. If you think you have any solution that would beat the NSA at targeted surveillance, you are dead wrong.
In the meantime, not trusting a third party server with a password would go a long way toward defeating dragnet surveillance. Read the reports. NSA defeats your SSL routinely, and they are MOST INTERESTED in the part where you supply a server with a password. They can only bust SSH some of the time. There is a very real security difference between the two.
Snowden got exiled bringing you the news. At least have the decency to read it.
That's a retarded retort. In the SSH case you have ONE password to remember. Not one per website. Furthermore, the password never leaves your machine. Log in to a hundred websites with SSL and a password and the NSA comes along, collects all your passwords server side, knows which ones you reuse, knows your password generation patterns, everything. You are completely nuts if you think these two things are the same.
<keygen> can generate client side keys. It's not very good, but it exists.
Brilliant, right? No, because user accounts are commonly shared
Gee, I guess only I can drive my car. If only there were some way to share my car with my spouse. Like having a second set of keys or something...
Yet, if you call a public key/private key a lock/key respectively, then a lot more people would immediately get the concept.
"You send him a copy of your lock which he uses to lock a package and return it to you. Then only your key can open it!"
You immediately fix the problem of people sending their key, because people know keys are important and shouldn't be handed out to just anyone.
The PKI people are brilliant. Their communication skills, not so much.
I am not sure about this. First, there is a built in MITM attack here.
This always sounds like a NSA shill argument to me. Sure, you can MITM, but then, you HAVE to MITM on the very first request of every user to make that work. That's much more expensive than vacuuming up passwords server side with gag orders.
Second, ssh keys are somewhat limited... You cannot embed identity info in the public key.
That's ridiculous. Who would want to? You are looking for an authorization solution. SSH is for authentication.