4 ms·
I disagree that passwords are a browser con, especially given the number of people who leave their phones lying around or let friends use them. If the app deals
by Trezoid 14y ago
I disagree that passwords are a browser con, especially given the number of people who leave their phones lying around or let friends use them. If the app deals with anything sensitive (and email can certainly be one of those) it should require a password every time.
Imagine if someone found your phone with email logged in. They would immediately be able to scan through your email for registration confirmation emails, go to that site and reset the password giving them complete access. If one of those accounts was for a site which saved cc details and had something the thief wanted (or could sell), they can drain your card with out setting off any fraud warnings, because you wanted to convenience of not having to type your password every time.
- pkamb 14y agoAnd then you have something like the iTunes Connect app, where you constantly have to re-enter your long password on a small touchscreen keyboard. I've basically stopped using the app because of it.
- bunderbunder 14y agoI want to agree, but website passwords are a usability nightmare for mobile users. Take all the hassles that come with sites having eleven million mutually incompatible sets of requirements for passwords, and throw on top of that that typing them on a phone's keyboard is slow and error-prone. Only password-compulsive geeks are going to go for that option. Your average user won't. For them, it's a huge con. I agree that it's troublesome that people have their phones set up so that anyone with physical access to an unlocked phone has access to everything. But I'm inclined to think of that as a symptom of the problem rather than the problem itself. The root of the problem being that too many folks who draw up security schemes don't seem to grasp the most basic lesson about how people deal with security: When given a choice between excessively inconvenient security and no security, your average user will always opt for no security. If that's not an option by default, they will figure out a way to make it an option, and then opt for it. (Sticky notes, y'all.) If there's no way to make it an option, they will go find someone who lets it be an option, then opt for it.
- reddit_clone 14y agoBiometric authentication can be a way out of this difficulty. A fingerprint scanner at the back of a smartphone will be a painless way of logging into anything you want.
- bunderbunder 14y agoAs long as it can't be defeated with scotch tape and gelatine. One great thing about non-biometric authentication systems is that it's easy to replace a compromised keycard or password. Replacing your own fingers, not so much.
- reddit_clone 14y agoWell, if you don't mind using a complex password on a keyboard-less device, the whole discussion is moot. Aren't we talking about alternatives to conventional password entry because it is a great nuisance? Voice recognition, Face recognition and Finger Printing all seem reasonable alternatives. I do believe it is a matter of time before they become viable in smartphones. How about an RFID chip in your wrist watch which makes your smartphone log in. Outside of a meter or two, it will ask for a complex password. Why not? I will buy it :-)
- gte910h 14y agoNo, it's not painless, it's raising the stakes: They have to steal your actual body parts, which would literally hurt.
- reddit_clone 14y agoIt did occur to me. If your information is _that_ valuable then you have a different class of problem than the inconvenience of entering a password on a device with a soft keyboard.