|
|
|
|
|
by nickf
132 days ago
|
|
You are correct, and the answer is - no-one using publicly-trusted TLS certs for client authentication is actually doing any authentication. At best, they're verifying the other party has an internet connection and perhaps the ability to read. It was only ever used because other options are harder to implement. |
|