Instead of all their hand-wringing about client security, operators of consumer Web sites should implement support for client certificates, thereby replacing or enhancing the registration process. And instead of waiting for the user to obtain a client certificate, ISPs should just issue one when the user signs up. Client certificates are no less secure than the consumer authentication methods used today. CA (Certificate Authority) and e-business sites should provide incentives for users to obtain stronger certificates as needed.
ReadThe reader feedback to my May 15 column regarding the impact of fat clients on scalability was, "Are fat clients all that bad?" The rest of the mail I received questioned the alternatives to loading all of the applications on the client.
Read