Live data from Hacker News

Why even let users set their own passwords?

devever.net

361–370 of 392 posts

Re: Why even let users set their own passwords?

#361

Earlier quoted context omitted.

I hate the fact that if you lose your phone and restore to a new one, suddenly every app is logged out again. Like can't the login-state be part of the backup? If I was logged in when the backup was taken, I should still be logged in when restored to a new device.

I think if you do an encrypted itunes backup to your mac, they should remain signed in

Note that this is now in Finder, not iTunes, as of.. some recent MacOS? 11?

Re: Why even let users set their own passwords?

#362
post #358
post #335

Earlier quoted context omitted.

> people...who would like to disable JS, but it's just not practical As I tell my kid when he "wants" something, I want a pony, and a million dollars. I don't see why the fact that some people might like that matters. I mean, given the choice for free sure I'd "like" it too. But it will never remotely be worth it to build two entirely separate web applications for every website to make that dream a reality, nor do I…

Look. I agree with you, in the core idea. There have really been advances in technology, but for each step made with brilliance and prowess, there have been 3 steps back with laziness and carelessness. Some applications of the newer technologies merit their use. Most use cases, however, don't. Bad practices abound, the "art" of programming becomes a chore made by let's say not very skilled people. Luckily there are s…

Maybe I'm just too old but it feels like humanity will always find a way to collectively fuck everything up. The web is always going to be shit. Fortunately another contingent of humanity invented uBlock and reading mode.

Re: Why even let users set their own passwords?

#363

Earlier quoted context omitted.

The author is Hugo Landau, so of course it is a bad take, how else could it be. The real question at this point is why his terrible takes reach the front page every two weeks…

Seriously, reading this article made me wish for a downvote option on submissions. I'm glad the top comment is pointing out the nonsense of this argument, but then I'm just left wondering how this made it to the top of HN in the first place. The author's diatribe about "remember device" functionality is just flat out silly, for all the reasons other commenters have pointed out.

> I'm glad the top comment is pointing out the nonsense of this argument, but then I'm just left wondering how this made it to the top of HN in the first place.

The last two posts from the same author[1][2], in the past month, where of the same kind and got the same kind of reception (except that for the fediverse blog post, the top comments were either discussing about the topic of the title without addressing the (dumb) content of the article). So yeah, the mystery is why it keeps coming back.

[1]: https://news.ycombinator.com/item?id=36549218 [2]: https://news.ycombinator.com/item?id=36466133

Re: Why even let users set their own passwords?

#364
I had a very different idea of what this article was going to be about before I read it. Since the article is kind of an irrelevant rant, let me share what I thought the title was encapsulating:

Corp policies asking users to change their passwords every 60 days or whatever, combined with the ever-more-arcane password content requirements -- yes, why the HELL are you asking me to change my password? I'll just go to one of the online passgens, generate a string, and immediately save it in a text file in my local home directory, because there's no way I will remember it.

Might as well generate passwords for your users already. Don't email me asking to come up with my own, send me a link to a form where I can copy the new password from.

Re: Why even let users set their own passwords?

#365
post #302

This is basically exactly what WebAuthN/Passkeys is, right?

That's like saying: IPv6 is basically IPv4 with bigger addresses, right?

It’s like saying “we shouldn’t have to worry about ip address starvation”, and having IPv6 as exactly the solution

Re: Why even let users set their own passwords?

#366

Earlier quoted context omitted.

>- we lose contact with people because they get locked out of their email I've been locked out of my email because Google insists that "we don't recognize your device", and locked out of my other accounts because my phone was stolen , not because I didn't remember my password. People forgetting passwords isn't a problem that's solved with other schemes. It's a problem that's exacerbated by them. >- we pay more in ban…

> People forgetting passwords isn't a problem that's solved with other schemes. Sorry, I should have clarified: that was in reference to users being unable to successfully use the parent's hypothetical 'terribly complex 5FA device-based passphrase scheme'. Passwords don't get any blame here. > Bank account fees, seriously? I can't remember the last time I've paid any. OK, fractionally lower interest growth then, or l…

Ah, thank you for the clarifications! I agree with all of the above.

Re: Why even let users set their own passwords?

#367
post #302

Earlier quoted context omitted.

That's like saying: IPv6 is basically IPv4 with bigger addresses, right?

It’s like saying “we shouldn’t have to worry about ip address starvation”, and having IPv6 as exactly the solution

Righ, so 20 years from now we'll all still be using passwords while a few people play around with webauthn

Re: Why even let users set their own passwords?

#368
post #354

Earlier quoted context omitted.

Calling such people “technological deadweight” and “free riders” is the insensitive thing, regardless of the veracity.

That's your opinion. As a New Yorker my personal opinion is that people are, if anything, too sensitive in interpersonal communication. Yet akin to the article, because of the overly sensitive, everyone's expressive creativity must be dulled down. Who's the intolerant one? Reminds me of this classic https://medium.com/incerto/the-most-intolerant-wins-the-dict...

Ah, that’s fair. My comment is phrased as though I’m presenting a fact. Perhaps “the things which are seen as insensitive” is better phrasing.

I can agree that people are often over-sensitive but I wouldn’t expect that calling a person deadweight is likely to garner their thoughtful attention, precisely because it is disrespectful. Indeed, it would be foolish of me to expect them to start (or continue) listening to my words.

Maybe you have better luck in New York but I bet you could find people (read: strangers whom you’ve never met or spoken to) there who are personally offended when you call them deadweight. If you’re walking somewhere and you see someone whom you think is homeless, do you let them know they’re deadweight to society? Do you think one is being over-sensitive if they become offended after they are simply called “stupid”? It might be worth explaining an opinion more instead of using such terminating cliches.

Maybe because the one commenter used the phrase “insensitive opinion” there is a misunderstanding. I’m not trying to suggest that the opinion is insensitive, only the way it’s expressed. This opinion can be presented in a friendlier way, despite the topic. (It may also be worth pointing to four words in my initial comment: “regardless of the veracity”.) One can be tolerant of opinions while being intolerant of name-calling in a way that is compatible with not being the “tyrannical minority”.

Re: Why even let users set their own passwords?

#370
post #298

Earlier quoted context omitted.

It is not because: 1. TOTP is time based, after 30 seconds it means absolutely nothing, you cannot recreate the 'secret key' from that number 2. with TOTP everything is well-known. TOTP will usually generate a 6 digit 'secret', this makes managing it very predictable: 6 digits = 1,000,000 options(including all zeros) we can easily calculate a good security margin like: 5 attempt - 5/1,000,000 = 0.000005% chance of su…

While you are technically correct, you are missing the whole point of the blog post

Seems like a rant to me.

Passwords are used because they are convenient and intuitive.

Once you use a 'password manager' you basically have a glorified key generator/storer

We already have so many alternatives from GPG keys to FIDO/FIDO2 solutions

Security isn't always the first priority when running a website/app, it is the sad but honest truth(coming from security expert with over a decade of experience)

Post reply on HN