Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Appreciate the "don't deviate from the norm" sentiment, but the norm is horribly broken for most users at the moment, and not deviating from it isn't going to make it better.

I'd actually challenge this assertion a bit.

Password management isn't as hard as it should be. I think Bruce Schneier is absolutely right when he encourages users to write down their passwords and store that paper securely -- in a wallet, purse, etc.

The problem, IMO, is that we've told users for years to "never write down passwords!" -- when, in reality, we should've been saying "write down a strong password and keep it safe."

>We learn from our screw-ups, not from dong nothing.

You're braver than I. Screwing up is expected, but security/privacy breaches tend to be among the least tolerated and most remembered screw-ups you can make.

If you do decide to pursue some sort of alternative credential system, it's in your best interest to get a consultation from an experienced security professional, as it could save you black eyes down the road.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: