Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We did, and they didn't want it. SSL client certs, maybe. There's Login with twitter, Login with Facebook. Login with Random Site X. Oh, don't like centralized third-party authentication? The only thing you know about security is that there needs to be a lock icon? Try something else, here's OpenID: distributed, federated, customizable. Oh, too hard to understand? Confused because the address bar changes? Why are you asserting your identity on site X when you want to access to site Y? Don't even know, or want to take the time to, understand what "asserting your identity" means? Well then we'll just let you log in with a username and password.

Oh, did you forget your username? Is your caps lock key on?

Even (edit: fake) celebrities known for crazy beards and drunken movies have an opinion on login security: http://twitter.com/GALIFlANAKIS/status/77372216957861888



that isn't his real account, some of "his" latest tweets: http://twitter.com/#!/GALIFlANAKIS/status/77450156102004736 http://twitter.com/#!/GALIFlANAKIS/status/77620921766129664 real account: http://twitter.com/#!/GALIFIANAKISZ they're using different letters and case. I = l, i = L


Good point. I forgot to check for the "verified" icon (since twitter refuses to consider me worth "verifying"). I'll edit to reflect that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: