<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class=""><br>
<br>
</span>Right. And I think that's unacceptable, at least until we have TLS token binding or other solutions to elevate security. Which is in fact what they're doing, so it bears (sic) noting that even the people producing this nonsense know it's nonsense.<br>
<div class="HOEnZb"><div class="h5"><br></div></div></blockquote><div><br></div><div>sure.  i didn't say i agreed with it :-)  I'd love to see a solution where every device has its own unique certificate that is signed by the manufacturer's CA and stored in crypto hw that you can bind to your account (did something similar for a customer a few years ago before OIDC was an option) but thats an entirely different discussion... </div></div></div></div>