Live data from Hacker News

Why even let users set their own passwords?

devever.net

171–180 of 392 posts

Re: Why even let users set their own passwords?

#171
post #44

Earlier quoted context omitted.

I kinda wish there was something like cookies, but even more persistent. Lets call them permacookies. I want to "remember my device", and have that keep me logged in forever with a permacookie. I don't even want to have a username and password. I want to create an account and be forever logged in. There would be mechanisms to backup my permacookies, or transfer them to other devices. I'd have control of which sites c…

Honestly that feels like what apps are. One of the most compelling reasons to install an iOS app for something like an online bank is so that I won't have to worry about my cookies expiring and forcing me to login again.

> Honestly that feels like what apps are.

Almost every single app on my phone forgets who I am even after minor updates.

Apps I use infrequently? It's like they never knew me to begin with.

Re: Why even let users set their own passwords?

#172

> Often this will be combined with fallacious notions such as “remember this device”, the idea being you only have to go through all this the first time when logging in from a particular device. This idea is fallacious because the web has no notion of a “device”, and this is a very intentional design choice made for privacy purposes. We are literally living through the gradual phase-out of third-party cookies, amongs…

[deleted]

Re: Why even let users set their own passwords?

#173
post #131

Earlier quoted context omitted.

This is only true if you’re very selective about which threats you want to acknowledge. If someone breaks into my house I’d rather they just got my TV and some belongings rather than my life savings.

I'd wager that >99% of all burglaries are looking for physical possessions which can be sold for a quick buck. Not looking for random notebooks of passwords. So locking it in a safe might not be optimal because it will be like putting a spotlight on it.

Something like 90% of burglaries are looking for car keys. That's why I keep my keys by the front door in eyesight on anyone who comes in. I have insurance, and don't want a thug wandering around my house.

Re: Why even let users set their own passwords?

#174
This is the regular reminder that you can create your own password, provided it's created via a secret which only you would understand. Then you can store the secret safely.

It can't be your wife's name, or your birthday, your kids' names, car license, or anything which someone could research.

We've had this discussion before.

Re: Why even let users set their own passwords?

#175
post #32

I play a japanese gacha game and there is no password there for your account. If you want to login they send you a code to your email and then you use that (valid for 30 seconds). I'm not a security expert but I always liked that for some reason

Those are called "magic links"

Re: Why even let users set their own passwords?

#176
post #168

Earlier quoted context omitted.

I think you sell older people short on what they are and aren't aware of. I think it's more that they see computer technology as a necessary annoyance of the modern world and not anything helpful. They used to manage their bank balance on a ledger in the back of their checkbook, and that seems easier to them than having to sit down in front of the computer or use an app on a small screen that's constantly throwing po…

> There is no online payment method I've seen that seems easier to me than just writing a check. Autopay. I only pay one bill manually, twice a year, because they don't allow autopay (property taxes). Otherwise I just don't think about it. Sure, you may not like autopay for whatever reason, but that's a choice. The option is there.

Yeah and I do use autopay for some very predictable things like utilities. I'm not totally comfortable with giving someone access to draw from my checking account whatever amount they claim I owe, but realistically these days a paper check becomes an ACH payment so I figure there are non-zero chances for error that just cannot be easily avoided.

Re: Why even let users set their own passwords?

#177
I prefer so called “passwordless” systems that use a combo of magic links and 2 factor authentication. I do think passwords are an outdated modality for non local accounts, most of the time.

If anything they should only be used for resetting the account coupled with successful use of a 2nd factor, I suppose, but recovery keys aren’t a bad compromise depending on the user

Re: Why even let users set their own passwords?

#178

Earlier quoted context omitted.

It would be easier for you, who (I suspect) has, like most of us here on HN, a good understanding of what happens on a computer, how to control that, how to manage their software, how to be aware of what is on the foreground when and taking input when. How to recognise various applications and seeing the difference between materially different ones that try to look the same. Your notebook will look markedly different…

I think you sell older people short on what they are and aren't aware of. I think it's more that they see computer technology as a necessary annoyance of the modern world and not anything helpful. They used to manage their bank balance on a ledger in the back of their checkbook, and that seems easier to them than having to sit down in front of the computer or use an app on a small screen that's constantly throwing po…

> I think it's more that they see computer technology as a necessary annoyance of the modern world and not anything helpful.

They are correct aren't they? None of the modern software is made to serve and help the user. It's made to serve advertisers and be promotion vehicles for product managers.

I am a computer guy. I am constantly and continuously irritated by all the crap in software. I see how my non-techie mom struggles, and it's several orders of magnitude worse for her.

So I totally agree with you.

Re: Why even let users set their own passwords?

#180

Earlier quoted context omitted.

I think you sell older people short on what they are and aren't aware of. I think it's more that they see computer technology as a necessary annoyance of the modern world and not anything helpful. They used to manage their bank balance on a ledger in the back of their checkbook, and that seems easier to them than having to sit down in front of the computer or use an app on a small screen that's constantly throwing po…

I am not at all claiming that all people above a certain age have difficulty with these things! Though it is usually people above, say, 40 who feel this way — and this is not a negative thing: it may well be just because they remember that a different way existed. I.e. most people with tech difficulties are older, but many older people have no tech difficulties. Though you are also correct that dealing with "technolo…

> Though it is usually people above, say, 40 who feel this way

and immediately you write this:

> Though you are also correct that dealing with "technology" today requires a certain level of pain tolerance. Good UX exists but is rare

So it's not just 40+ year olds who feel this way

Post reply on HN