Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Except that's a bandaid over existing solutions. It's hard to imagine in 50 years we'll still require people to remember both a user identifier plus a password.

It's a tough problem. Human memories are fallible, yet it's with you always. Passwords can be given to others, which can be convenient in many situations (something bio recognition can't do). Bio markers like fingerprints are left everywhere as CCC has demonstrated, or the markers themselves can change such as with Macular degeneration in eyes. Phones can be stolen or run out of battery, physical key cards lost, and centralized systems like RSA's SecurID hacked.

In a lot of ways the banks have it done best, with combining a replaceable physical object (loanable) with a short PIN (sharable and more memorable), and then throwing fraud detection on top of it. It's the last piece that's the best and also the least available for others to do easily.

The problem would be better addressed by having a turn-key solution that any company can easily plug into their code to detect fraud attempts on short passwords. Big hole waiting for a startup to fill...



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: