[ Thanks to Eddy
Nigg for this link. ]
“The same type of certificates may be also used for
authentication purpose as the StartSSL™ Control Panel readily
demonstrates. There is no way to steal, phish or otherwise
compromise a StartSSL™ account, because simply no user name
and password pairs are used here.“Similar secure is the OpenID Identity provided by
StartSSL™ which may be used at various sites which support
OpenID for authentication purpose. Strictly over SSL secured, this
OpenID provider uses digital certificates exclusively for
authentication.”