Hacker News new | past | comments | ask | show | jobs | submit login

If you google passwordless, biometric solutions are one way to go, hence I mentioned them, not because I wad trying to put it into your mouth.

If someone has access to my password they either got it by torture, a non or insufficient hashed store on the other end or by breaking encryption.

A simple dongle that may not even need a password, is easier to get.

2FA can make sense, passwordless does not.

The risk of 3rd party screwing up, doesn't go away, it's just shifted to another 3rd party, which again, you have to trust.

I use a different email address with a unique password for anything that's important and where another person having access could harm me. Forums and such are not a part of that.

So let's agree to disagree. I'll stay with passwords for everything that's important and for most things that are really important, apart from banking that is, I don't even have a 3rd party involved.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: