4 ms·
Q: If someone were to steal your HN password... whats the worst that could happen? A: Not much. It would seem extra security layers wouldn't provide much bene
by Mamady 14y ago
Q: If someone were to steal your HN password... whats the worst that could happen?
A: Not much.
It would seem extra security layers wouldn't provide much benefit.
- drcode 14y agoThe only person who could get hurt is the one who uses the same password for HN as they do for their bank. Is it the responsibility of the website developer to protect that person from themselves?
- erujolc 14y agoNot on HN unless you're retarded
- corkill 14y agoProtect them from themselves no. Protect their password as much as possible when interacting with your web app/website I would say yes. I don't think about it as a responsibility rather just a nice or the right thing to do.
- manuscreationis 14y agoI would definitely say it's the responsibility of the application developer to secure user account information, in addition to being the nice/right thing to do.
- manuscreationis 14y agoSince you made the same comment more than once in this thread, I'll reply to you here as well. This attitude is absolutely not ok. You need to make sure the security of users accounts if a top priority, even if your app is 100% trivial in nature.
- manuscreationis 14y agoThis is probably the worst possible response anyone could give with a question like this. I sincerely hope you're either joking, or in no way responsible for the security of user accounts wherever you happen to be employed.
- Mamady 14y agoIm not joking at all. It's not as if HN is "feature rich" - the short comings are spread across the board, why should they implement a multilayer login security system but skimp on everything else? Have you ever done PCI compliance? Login is the tip of the iceberg! But that is exactly my point - HN doesnt need to do this stuff or become PCI compliant, because they dont store (very) sensitive information. HN is a poor MVP at best. Its the community that makes HN amazing, not the product.