3 ms·
OpenID and OAuth really did a lot, but there's just nothing called "don't use passwords." Fingerprint readers suck. Anything biometric that doesn't suck costs t
by pmylund 14y ago
OpenID and OAuth really did a lot, but there's just nothing called "don't use passwords." Fingerprint readers suck. Anything biometric that doesn't suck costs too much, and 99% of people don't have them. A good KDF is not bad in comparison to a centralized authentication server considering other factors.
Someone, somewhere will be storing user passwords/digests for the foreseeable future. And they will do it incorrectly.
- stickfigure 14y agoSure, but the number of those people should become vanishingly small over time. HN is full of web developers rolling unnecessary username/password solutions. The fact that this is such a hot issue - as opposed to esoterica like TCP frame size - shows that far too many developers are homebrewing solutions rather than outsourcing.
- pmylund 14y agoI agree, but "outsourcing" includes using libraries written by people who know what they're doing. (And not using libraries written by people who know what they're doing, but which are the wrong tools for the job.)
- DanBC2 14y agoFravia used to talk about dongle protection. He was impressed with some of the dongles and the libraries, saying that they were basically secure. But he was not impressed with the ways that companies implemented those dongle protections - sometimes not bothering with any of the advanced features and just using a stupidly simple "dongle present? then run software, otherwise show nag screen" test. Would this be a problem with hashing libraries? Are there any that require very little knowledge for people to implement them correctly?