Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think from most people's perspective all those things do is make login sharing harder. I'm working with a non-profit to set up a website and social media accounts, and I've explained the concept of everyone having their own login to a shared account 3 times, and I think maybe 1 person gets it. (And maybe I suck at explaining it, but I have plenty of teaching experience and usually get compliments on explaining technical stuff in a non-jargony way).

If these same people had the obstacle of having to add another person's phone to 2FA as well as share the password, they still wouldn't look very long at alternatives to the way they log in. There's a fundamental assumption that there's a way to log in, and other people just have to do that. Very hard to help them realize that everyone should authenticate as individuals, and you can authorize individuals to access the group's resources.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: