Live data from Hacker News

43M passwords hacked in Last.fm breach

techcrunch.com

171–172 of 172 posts

Re: 43M passwords hacked in Last.fm breach

#171
post #121
post #77

Earlier quoted context omitted.

It's really a shame that we haven't solved this problem yet as an industry. I was thinking we could build a general purpose version of "Magic Links" for logging in, where the format of the email is well-defined, and the user's browser is able to receive these messages on their behalf through some form of integration. You could imagine a webmail provider offering some kind of polling or websocket API for listening for…

The problem is twofold: - whatever solution we come up with needs enough market force to push adoption - whoever gets to own "single sign on" owns the world. This is why there was so much backlash against Microsoft Passport all those years ago. Personally I'd favour some sort of hardware token, and we're very slowly moving in that direction with U2F.

There are already Gmail/Microsoft/Facebook providing single sign on for users.

That doesn't mean applications are bothering to support them.

Actually, Facebook is ubiquitous for popular apps to the point it's often mandatory. (too bad for privacy :( )

Google App for business (and Microsoft to a less extent) have market shares among professionals but many SaaS and hosted applications cannot integrate with it at all.

Re: 43M passwords hacked in Last.fm breach

#172
post #168

Earlier quoted context omitted.

OpenID registration is the solution to this problem.

OpenID is dead thanks to OAuth. I hope IndieAuth could get some traction but the problem with it is that every user needs to have their own tld domain but many registrars and dns services don't even use two factor authentication.

Actually, it's now called "OpenID Connect" and it's a profile of the OAuth spec.
Post reply on HN