Hacker News new | ask | show | jobs
by growse 4586 days ago
Given that it's possible to memorize a certificate, it definitively cannot be a 'something you have' factor. Something you have is more than just data. A client cert is nothing more than a fancy long password.
1 comments

The base64-encoded SSL certificate for *.ycombinator.com is 1,755 characters. Maybe there are a few savants in the world who are capable of memorizing that, but for the overwhelming majority of human beings, it's never going to happen.
Point is, it's information. It's very easily copied. The whole point of 'something you have' is that it's not just data, but something more than that.