Live data from Hacker News

Stop Sharing Your Twitter Credentials

blog.twitpay.me

1–10 of 34 posts

Re: Stop Sharing Your Twitter Credentials

#3
post #2

"since they don’t yet offer OAuth" OAuth wouldn't solve the problem though, it'd just move it somewhere else. Use a different login for each site - use a password manager.

That's a good point. OAuth would at least centralize the problem towards a more trusted source and limit the number of places the credentials would be stored. I trust Google or Facebook to have more safeguards in place than a webapp that popped up yesterday. As for password managers, I totally agree people should use them, but as a practical matter, most non-tech people do not.

Re: Stop Sharing Your Twitter Credentials

#4
post #2

"since they don’t yet offer OAuth" OAuth wouldn't solve the problem though, it'd just move it somewhere else. Use a different login for each site - use a password manager.

Agreed on the password manager. I've got 1Password in Safari, and the "Generate Password" option is so easily available it becomes second nature.

Re: Stop Sharing Your Twitter Credentials

#5
post #3
post #2

"since they don’t yet offer OAuth" OAuth wouldn't solve the problem though, it'd just move it somewhere else. Use a different login for each site - use a password manager.

That's a good point. OAuth would at least centralize the problem towards a more trusted source and limit the number of places the credentials would be stored. I trust Google or Facebook to have more safeguards in place than a webapp that popped up yesterday. As for password managers, I totally agree people should use them, but as a practical matter, most non-tech people do not.

You trust Google to control all your logins ;) I have a cautionary tale to tell about that one...

Re: Stop Sharing Your Twitter Credentials

#6
post #5
post #3

Earlier quoted context omitted.

That's a good point. OAuth would at least centralize the problem towards a more trusted source and limit the number of places the credentials would be stored. I trust Google or Facebook to have more safeguards in place than a webapp that popped up yesterday. As for password managers, I totally agree people should use them, but as a practical matter, most non-tech people do not.

You trust Google to control all your logins ;) I have a cautionary tale to tell about that one...

I cetainly don't trust them to control all my logins. But my level of trust for them is much higher than for most in terms of their ability to secure their databases and applications. I use different levels of passwords, depending on the type of site: nytimes.com < gmail.com < bankofamerica.com. I have tried to use password manager, and am currently trying one out on Safari, but the use of many computers makes it difficult.

Re: Stop Sharing Your Twitter Credentials

#7
post #4
post #2

"since they don’t yet offer OAuth" OAuth wouldn't solve the problem though, it'd just move it somewhere else. Use a different login for each site - use a password manager.

Agreed on the password manager. I've got 1Password in Safari, and the "Generate Password" option is so easily available it becomes second nature.

Sounds like that would make it much harder to switch browsers...

Re: Stop Sharing Your Twitter Credentials

#8
post #7
post #4

Earlier quoted context omitted.

Agreed on the password manager. I've got 1Password in Safari, and the "Generate Password" option is so easily available it becomes second nature.

Sounds like that would make it much harder to switch browsers...

Speaking only of 1Password, they have plugins for most, that share the same database. Also syncs to my iPhone.

Re: Stop Sharing Your Twitter Credentials

#10
post #9
post #2

"since they don’t yet offer OAuth" OAuth wouldn't solve the problem though, it'd just move it somewhere else. Use a different login for each site - use a password manager.

http://duckduckgo.com/?q=pw

I prefer https://www.grc.com/passwords.htm for my random password generation needs...
Post reply on HN