Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because we've known about credential reuse for 20+ years, developed multiple means to keep a site secure when it happens and then chose to not employ those security measures on data people broadly consider incredibly sensitive.

It is your job as a service provider to not allow access to anyone but the authorized user, how you do it is an implementation detail. You can't throw up your hands and say "well we decided that doing that is too hard so we're defining the authorized user as anyone who knows the password."



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: