by NaNaN on 12/3/14, 1:12 PM with 4 comments
If you use GPG public/secret keys, then you don't need email for password retrieving any more. (and no email spams about that)
1. For registrations, upload your public key and use your secret key to verify that you own the public key. 2. Retrieve your user password is simple, too. The server encrypt some text with your public key, then you use the secret key to decrypt and submit the original text to verify.
Nowadays, more and more people use password managers to generate strong passwords. Why not use GPG? Is any website using GPG for password retrieving?
by rprospero on 12/3/14, 2:42 PM
To put it differently, if you have gpg authentication available, why are you even bothering with a password in the first place?
by valarauca1 on 12/3/14, 1:18 PM
You are welcome to try.
by hakanderyal on 12/3/14, 1:30 PM
Something like that must be easy to use, and easy to understand to be used by the masses.