3 ms·
We need to re-think passwords. Password re-use is a big problem for technical and non-technical users alike, because managing a unique generated password bet
by fps 10y ago
We need to re-think passwords. Password re-use is a big problem for technical and non-technical users alike, because managing a unique generated password between devices is hard. Dealing with password managers and syncing password lists back and forth is super frustrating to users. None of the existing tools work quickly and easily on all the different devices a user could be using, so at some point everyone that uses a password manager is going to be stuck fighting their password manager to log into a website. The user will likely perform a password reset, which will send an email that allows the user to bypass the password entirely.
Why not provide people with a quick and easy "login by email", since this fallback is almost always available anyway? Slack does this https://auth0.com/blog/how-to-implement-slack-like-login-on-ios-with-auth0/ https://auth0.com/blog/how-to-implement-slack-like-login-on-... and allows people to have accounts with no password memorization. You're not making the login any less secure - any attacker with access to a user's email can almost always perform a password reset anyway.
- whyever 10y ago> Why not provide people with a quick and easy "login by email", since this fallback is almost always available anyway? There was Mozilla's Persona (which was shut down a few days ago). Now there is this: https://portier.github.io/ https://portier.github.io/