5 ms·
For every user like you who is using unique, securely generated passwords in a manager, there’s 10,000 people who are using the same, easily compromised passwor
by osdiab 7y ago
For every user like you who is using unique, securely generated passwords in a manager, there’s 10,000 people who are using the same, easily compromised password on every website they’re registered on.
You’re not the target audience for these features - not only are you the tiny minority, but no matter what system they give you, you’ll find a way to interact with it safely, so for that interaction you simply don’t matter.
And choosing to do this kind of login pushes blame for authentication issues away from that company, and onto the federated provider, who presumably has legions of security researchers to make sure they’re doing things safely.
- netsharc 7y agoHuh, new idea, Google already prompts me on my phone when I log in to Google on a new device, why isn't there a service where instead of having to open my email and find that darned Medium email, it can push a question to one of my devices (also on PC) and I can just press "Yes that was me, let me in"? It can be some third party so I don't need a different software for each site..
- Spivak 7y agoIsn’t that basically logging in with Google? I mean Google isn’t asking you if you logged into Medium with a push but by the time you’re doing that Google already knows it’s you and pushed you a notification to log you in initially.
- netsharc 7y agoAlmost, but what if I'm uncomfortable with Medium having my real name and profile pic (which Google's SSO will share)? I'd imagine Medium would offer "authentication through X", and I can either enter my id for X, or go to the X app and generate a new ID for use for Medium, and paste it on Medium. So next time I want to login to Medium, after entering my username, Medium's backend talks to X's backend (saying user with this ID wishes to login) X can prompt me on one of my devices. Medium can display a unique number on their page for me, and I can compare that to the number my X app is showing me to confirm it's me I'm letting myself in. This is a 1 minute concept without considering creative ways it can be attacked. But I guess there wouldn't be any money to be made...
- lazyasciiart 7y agoI don't care. All they have to do is not ruin the experience for me, not make everyone else use it.