2 ms·
I don't know enough about OpenID to comment on it. In the quoted sentence I was pointing out that it's not unusual for websites to be completely unaware that t
by socillion 13y ago
I don't know enough about OpenID to comment on it.
In the quoted sentence I was pointing out that it's not unusual for websites to be completely unaware that they were hacked. It would certainly be unfounded to assume a service couldn't be compromised.
I think it's unreasonable to ask consumers to maintain a large variety of unique passwords. It's a noble goal but it just doesn't happen. LastPass/1Password do solve the password duplication issue, but at the cost of centralizing your passwords and having sites still manage authentication.
Why trust every site you sign up for to properly handle nuances like password character limits and account reset protocols, what if sites let a third party with a narrow focus handle these details?
Password managers are an easier solution to implement, but I don't think they are better than a well designed solution that's similar to Mozilla Persona. If you think otherwise, I'd be happy to hear why.
- stephenr 13y agoThe problem with your suggestion is the phrase "third party with a narrow focus". There are dozens of OpenID providers. The majority, and certainly all the major ones, offer it as part of another service, i.e. Google, Yahoo!, etc. So to authenticate with some-guys-website.com you want me to then register an account with a third party, because that's better than having a different password for this site? The likes of Google, Yahoo, etc already have way too much information about what people do, you seriously want to force people to give them more? I freely admit that there is a problem with the current system, but the solution is not dumping the concept completely and just trusting the likes of Google for authentication everywhere. It's perfectly possible to have very strong password hashes (e.g. bcrypt/blowfish, scrypt, PBKDF2) but when you have idiot developers, you get bad results.