3 ms·
Yes because that's the same as requiring two passwords. It's even more secure to get three or five. But using the email address serves a different purpose, peop
by sfopdxnonstop 8y ago
Yes because that's the same as requiring two passwords. It's even more secure to get three or five. But using the email address serves a different purpose, people rarely forget them.
- quickthrower2 8y agoNot really, in the event of a leak, two hashed passwords leaks less information than a hashed password and an email address. Why have 2 not 1. Well one of them has to be globally unique on the site, the other has to be hard to guess. Two different requirements.
- groestl 8y agoYou can say that for sufficiently high values of hard, "hard to guess" implies "globally unique".
- cortesoft 8y agoIt is also a built in way to do password reset, and they are automatically globally unique, by definition.