3 ms·
How many years have we been hearing username/password auth is outdated and difficult and stupid and insecure? Fifteen? Twenty? Something like that at least, and
by interfixus 8y ago
How many years have we been hearing username/password auth is outdated and difficult and stupid and insecure? Fifteen? Twenty? Something like that at least, and I'm headbangingly tired of it. As tired as of the two factor idiocy popping up everywhere these days. Latest offender I've run into is Digital Ocean, who might otherwise have lured me back with a recent promotional offer. But no, they had to go and ruin it by plastering me with emails and codes and whatnot every single time I tried logging in, presumably because I like to get rid of my cookies the instance I leave a site.
Listen, passwords are not hard to use. Mine are 256 bit and utterly random everywhere they are allowed to be. I manage them responsibly. It's not a hassle, anyone can do it, there are great tools for the job. I do not want any centralised single sign-on solutions or other fancy hocus pocus, I do not need them, and I feel - increasingly - penalised for the laziness of those who can't be bothered.
So, in short, whatever this is about, I can only hope it fails like so many other attempts before it. The Log in with Google & Facebook buttons proliferating on every second site out there are plenty bad enough.