Hacker News new | ask | show | jobs
by Tadpole9181 872 days ago
Any such ID would need to be validated by the service. Therefore the service and the authenticator would need to speak. And in doing so, the authenticator will be able to see that an ID issued to you is being used for that service.

You cannot get around this. The service must confirm with the authenticator. The authenticator must know you are authenticated, and be extension, who you are.

1 comments

Your comment is incompatible with mine, so one of us must be incorrect; I will leave it at that.