Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
The Password Isn’t Dead but It’s Quite Ill (idpro.org)
2 points by mooreds on Feb 1, 2022 | hide | past | favorite | 1 comment


For business-related services, SSO is the easiest approach. It is nice for employee (only one password) and nice for employer (centralized logging and control).

For personal, there is a push for SSO via Google or Facebook, but I think this is pretty dangerous. Google/FB can ban you forever for no reason and there is nothing you can do about it. So passwords, together with appropriate password manager, rule.

In fact, I could argue that password + password manager is superior to most "passwordless" login systems. Both of those give you one-click login as long as you have appropriate software installed. Both of those generate unique credentials to each website. Both of those could sync credentials across devices if desired (and if you trust their cloud service). Both of those a vulnerable to computer compromise. But password manager gives you much more options -- for example, you can have passwords stored on the paper or in a separate database. Or you can share /rotate password for one service without affecting all others.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: