6 ms·
The standard login/sign up form is broken, though. People will just use the same password across websites or write it down. You can't win
by nsgi 4y ago
The standard login/sign up form is broken, though. People will just use the same password across websites or write it down. You can't win
- chedabob 4y agoHopefully this should change over the next few years with both iOS and Android adding support for FIDO Passkeys. It's not new tech, but now that two huge players have put it in the hands of millions of users, it should pick up speed.
- m00x 4y agoUse a password manager. Problem solved.
- antioppressor 4y ago
- forty 4y agoDo you also use one computer per account? ^^
- antioppressor 4y agoWhy store passwords that are only used once per half a year with other passwords?
- Karellen 4y agoWhat's your preferred password management solution, and what do you see as its pros/cons over a dedicated password manager?
- pmontra 4y agoI do and tell people to do the same. Unfortunately we can't force people to actually do it.
- pvorb 4y agoUnpopular take: users should be free to use bad and insecure passwords for services they don't care about.
- type0 4y ago\popular take: they shouldn't use services that they don't care about
- wizofaus 4y agoUnfortunately even privileged users (that have authority to change the permissions or possibly passwords of other users) can still use weak passwords. A better solution would be to have your browser prevent you from reusing passwords (it only needs to keep hashes).
- parminya 4y agoIf the web browser is governing the passwords you can and can't have, and forcing you to have unmemorisable passwords, you're better off rethinking the whole thing. For instance, it probably makes more sense to ask the web browser to generate keypairs rather than passwords if we know the passwords cannot possibly be memorised.
- wizofaus 4y agoI don't reuse passwords, or use a password manager. I just have a system for remembering which password to use for each website, and maintain a list of hints. And I have a pretty terrible memory. But having had the password I used to re-use across a few (non- critical) sites show up on haveibeenpwned it's what works best for me.
- shakna 4y agoThat turns all users into a greater threat in the case of any bugs in the server. Makes it easier for the service to get DOS'd by authenticated users, and so on. Allowing on user to be more insecure, makes all users more insecure.