Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I hope these services have an opt-out. I know, I know, this will get infinitely more accurate at an arbitrary point in the future, and that I won't have complaints then.

But I get screwed constantly while travelling to other countries, getting repeatedly locked out of Gmail. Again, most users won't face these issues. But I don't want to live in a world where if you're not a nominal case, you're screwed.

The people who think passwords are hard will keep getting older and will be washed away. The generation coming in thinks paper is a broken iPad. So exactly, why do we need to solve the problem of passwords, when even slightly savvy users can handle it. Is it so hard to figure out that not too long in future, you can expect all your users to be comfortably savvy?

Also, passwords are deterministic and are a better UI. The Android Lollipop's on-body smart lock, for example, is pure non-deterministic headache. Haven't we gone through this with automatic sliding doors already?



> The people who think passwords are hard will keep getting older and will be washed away.

I wonder if younger generations use more secure passwords. I'd guess that the typical user does not.


Nope. Passwords used by them young folk just fit the requirements, and nothing else. Now, geeky XKCD readers probably use a variant of correcthorsebatterystaple, so we've got that going for us.


A temporary way to opt-out of some of these things might be a good thing.

I am on the glass half empty side of if user passwords will improve on a scale required. Even if you get to 90% of users using a good enough password, that still seems too low. For an average user, it is difficult to use a different password AND remember it, and that barrier probably will not change much. Many users still aren't going to start using a password safe.

The article mentions but dismisses multi-factor as degrading the user experience. But I think with the dominance of mobile devices, that providing a simple multi-factor token has become easier than carrying an RSA dongle. I find Google's use of the SMS token to be quite convenient.


I agree on multi-factor point. Recently, some apps even grab the SMS automatically and authenticate. I was surprised early this week, an app actually grabbed my MasterCard Securecode OTP, automatically filled it in and pressed submit. So degrading user experience of OTPs is not very true on mobile.

Moreover, in the mobile dominant world, use of public computers is very less. So typically an authenticated session would last months or years, rather than a few hours. So it is less of an annoyance.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: