Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Problems: 1) email is insecure, 2) it requires two logins, 3) it's not dual factor, 4) it's more error-prone. It's less work [and more secure] to just implement Google or Facebook authentication.

In terms of generating a strong password: most browsers have password generators (which I didn't even know about until recently). They aren't all enabled by default and they don't work on all forms, and not all browsers have them. Browsers also have supported user certificates [which are more secure than passwords, sort of] for like 15 years, but nobody ever uses them. The main reason (afaik) is how shit the browser's UX for them was, in combination with a burden of complexity - and of course you can't use them on random public devices.

I think we are close to reaching an authentication nirvana. If U2F came embedded in all new computing devices, and an open method of securely synchronizing all devices and service providers was used, we could effectively skip passwords, and rely almost entirely on backup codes for the few times they were needed. A lot of laptops and phones come with fingerprint scanners now. If those scanners were used as part of a U2F solution we would have a pretty solid authentication mechanism. (fingerprints are not foolproof, but IMHO they are about as secure as a password)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: