Earlier quoted context omitted.
> Apologies if I'm missing something, if it's easy to spin up unique identities on both what's the difference here? It seems like it would be one or the other. Yes except for a centralized entity the admin would have recourse. How does a web server admin deal with it in the case of blockchain? > I've seen posts on this forum about it. It happens and there's not much you can do if it does. If we are talking about anec…
> Yes except for a centralized entity the admin would have recourse. Can you be more specific? How is it easier to sniff out a user using multiple emails vs multiple keys? > If we are talking about anecdotes I’ve seen people lose their private keys to phishing and consequently all of their money, so… Losing your keys is a huge problem that needs to be solved. I think social recovery is super promising in that respect…
If someone made 2109@gmail.com 238@gmail.com 2398@gmail.com you could contact Google, send them the information and potentially block all of them collectively and/or find the person responsible. This would be important if your application has to do with financial activity. How would you do this if someone kept making random private keys?
> I'd argue for logins specifically it's less of an issue in the MetaMask world, as you do not need to expose your private keys for that. You need to expose your password to log into Google.
I'm not understanding you. If you're someone who won't use Google, or a centralized service, then you are capable of hosting your own web server. If you're capable of that an email address + password is superior to blockchain and gives you more control.
If you're not capable of that and are using centralized services for things like email then you lose no more control using their oauth server.
You and author have yet to address failure modes, or the superiority of this compared to email and password.