<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix">On 2015-08-18 1:38 AM, Matthew Turnbull
wrote:<br>
</div>
<blockquote cite="mid:55D2C4D4.2020004@bluefang-logic.com"
type="cite">
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
<br>
Maybe hindsight is 20/20, but at least to me, implementing a
password based system would have been simpler than implementing
all of the signing infrastructure across multiple system,
requiring devs change their process, and potentially disrupting
users ability to access the extensions they want.<br>
</blockquote>
Design decisions that shift the burden of working with the
weaknesses or shortcomings of a product to that product's users do
not typically result in happy, secure users or successful products.<br>
<br>
<br>
- mhoye<br>
</body>
</html>