Hacker News new | past | comments | ask | show | jobs | submit login

So, on one hand, I agree, password managers/FIDO should basically be part of every OS/browser and tech companies should come together to make it all interop seamlessly for the good of society.

On the other hand, the biggest barrier to adoption that I have found is people losing their master password. And supporting good account recovery is difficult and expensive. A subscription service that actually had a real way of validating identity for account recovery could be something worth paying for, for people who are not very tech savvy.

Maybe we can come up with a good account recovery service without dedicated customer support folks, but the moment you have a bad experience, you're probably going to go back to Password123.




Any possibility of account recovery completely torpedoes the product's security.


But in the real world, should there be account recovery, or wide spread password reuse where hacking random sites gets people's passwords to more important sites.


Neither. And that's a false choice.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: