Live data from Hacker News

Why even let users set their own passwords?

devever.net

181–190 of 392 posts

Re: Why even let users set their own passwords?

#181
post #2

Because for the average user it is still significantly easier to download some app to use in combination with a password they have a mnemonic for rather than having to figure out their own system for storing and retrieving long tokens in a reliable way. Also, most users are not obsessively clearing out their cache, so device recognition based password flows work seamlessly a lot of the time.

The system they will choose will be to get a new token by logining in with their email.

It will effectively be the same as those places that send you a login email after you have entered your password for security or harrashment (looking at you, Zoom).

Re: Why even let users set their own passwords?

#182
post #155

Earlier quoted context omitted.

Only 8 years late: https://developer.chrome.com/blog/push-notifications-on-the-... Besides - there are plenty of other things Apple can do to ensure PWA's don't take off. For example, there is no ability for a web-app to have a "click here to install to desktop" button - the website must try to guide the user into clicking the share button and then creating a desktop icon - which most users don't associate with 'inst…

Fascinating how to keep moving the goalposts. Firefox refuses to implement pwa. Chrome has pwas but they're not isolated. Apple is the only one with sane pwa but somehow they're the worst and are totally sabotaging PWAs because something something walled garden?

[deleted]

Re: Why even let users set their own passwords?

#183
post #168

Earlier quoted context omitted.

I think you sell older people short on what they are and aren't aware of. I think it's more that they see computer technology as a necessary annoyance of the modern world and not anything helpful. They used to manage their bank balance on a ledger in the back of their checkbook, and that seems easier to them than having to sit down in front of the computer or use an app on a small screen that's constantly throwing po…

> There is no online payment method I've seen that seems easier to me than just writing a check. Autopay. I only pay one bill manually, twice a year, because they don't allow autopay (property taxes). Otherwise I just don't think about it. Sure, you may not like autopay for whatever reason, but that's a choice. The option is there.

I highly recommend setting up autopay via your banks bill pay system. Less organizations having your account info is a good thing, and it’s super convenient for bill tracking.

Re: Why even let users set their own passwords?

#184

Earlier quoted context omitted.

You cannot save all people - too true. But remember that you, actually all of us, are indirectly the victim of other peoples' mistakes: - we lose contact with people because they get locked out of their email - we pay more in bank account fees to subsidise fraud compensation - we have our personal information stolen because others chose weak passwords Given how much we suffer from other peoples' poor choices, there i…

>- we lose contact with people because they get locked out of their email I've been locked out of my email because Google insists that "we don't recognize your device", and locked out of my other accounts because my phone was stolen , not because I didn't remember my password. People forgetting passwords isn't a problem that's solved with other schemes. It's a problem that's exacerbated by them. >- we pay more in ban…

> People forgetting passwords isn't a problem that's solved with other schemes.

Sorry, I should have clarified: that was in reference to users being unable to successfully use the parent's hypothetical 'terribly complex 5FA device-based passphrase scheme'. Passwords don't get any blame here.

> Bank account fees, seriously? I can't remember the last time I've paid any.

OK, fractionally lower interest growth then, or less frequent premium bond wins. In any case, the bank is going to find a way of passing the cost of business to you, so you have an indirect incentive for their business to be cheaper to them.

> If our info can be stolen because someone else chose a weak password, the weak password isn't the problem. It's the system that was badly designed in the first place.

That is correct for some kinds of personal information, like how storing documents on a 'cloud' without client-side encryption is a badly designed system for privacy. However, there are genuinely some occasions where a third-party needs to have access to (not just verification of) your information, but also has a responsibility to keep their copy secure. A hospital might need to see your medical records to do its job, for instance.

> The analogy doesn't hold because you have to first show that alternatives to passwords are better for the users, even those in the category you mention.

I completely agree with you. All I'm saying is that a lot of people will try to replace passwords (because we all have an incentive to improve the situation), even if their replacement fails at being better for users!

Re: Why even let users set their own passwords?

#185
Hmm, do I set my own password?

From the web site’s POV I certainly do.

But my password manager generates the password and remembers it for me and I only ever see it if the generated one somehow violates the site’s arcane password rules and thus requires a bit of manual manipulation. Which rarely happens.

Re: Why even let users set their own passwords?

#186

I appreciate that there is at least one other person on earth who shares my skepticism of many popular MFA implementations. A lot of them add more inconvenience than security. "We sent a code to your email" is particularly heinous.

Other than the chance the email is delayed, and the generally subpar UX, what are your concerns with emailed codes? This is an honest question, as this is the primary login method I settled on for all my services after spending a good chunk of time thinking about this.

For one thing, I now have to be logged in on my mail on the device I am using, and that means if the device is unsafe, I am exposing far more of a risk that way.

It also forces me to look at my email inbox, which can be a pretty annoying thing if I am trying to relax and now see some email with bad news - requireing me to break the flow again.

Most important however: it is simply wrong and not needed. The flow has been settled.

Re: Why even let users set their own passwords?

#187
post #59

Honestly, unless you're a major cloud/OS provider like Google/FB/MS/Apple, you shouldn't be managing passwords at all. Let the pros do that. You just use an authentication standard via a 3rd party. If you aren't big enough to maintain your own operating system and web browser, you shouldn't be storing passwords.

I agree social SSO is the gold standard in terms of UX, but it's also a privacy disaster. What we really need is for someone to make a Let's Encrypt for login. A nonprofit that provides SSO in a privacy respecting manner.

I agree. I'd much rather "login with Firefox Login" or "Ubuntu One" than Google or Facebook for SSO. But failing that, expecting end users to manage passwords to every site (and every site to store passwords) is still irresponsible.

Re: Why even let users set their own passwords?

#188
post #96

Earlier quoted context omitted.

Are you aware that iOS supports PWAs, and recently implemented notifications for them?

Only 8 years late: https://developer.chrome.com/blog/push-notifications-on-the-... Besides - there are plenty of other things Apple can do to ensure PWA's don't take off. For example, there is no ability for a web-app to have a "click here to install to desktop" button - the website must try to guide the user into clicking the share button and then creating a desktop icon - which most users don't associate with 'inst…

>50 MB excludes most messaging apps

The entirety of TempleOS (including dozens of programs and multimedia games) is 2MB.

Re: Why even let users set their own passwords?

#189

Earlier quoted context omitted.

I kinda wish there was something like cookies, but even more persistent. Lets call them permacookies. I want to "remember my device", and have that keep me logged in forever with a permacookie. I don't even want to have a username and password. I want to create an account and be forever logged in. There would be mechanisms to backup my permacookies, or transfer them to other devices. I'd have control of which sites c…

Password managers could take over and manage cookie storage/retrieval. Or browsers could treat cookies more like passwords and have a user-controllable flow on each new session: "Here's this site's cookies from your last session, do you want to place these back in the browser storage?" The fundamental issue is that browser cookies and password managers have an overlap in their usage domain.

Firefox remembers my passwords for me already. Why would I need an extra tool to do it? And so does Android.

Re: Why even let users set their own passwords?

#190
post #59

Honestly, unless you're a major cloud/OS provider like Google/FB/MS/Apple, you shouldn't be managing passwords at all. Let the pros do that. You just use an authentication standard via a 3rd party. If you aren't big enough to maintain your own operating system and web browser, you shouldn't be storing passwords.

I do not want to log in with Google or GitHub or Apple or anything else. I want an account on your site, even if you're bad at security (though you should at least store hashes and not plaintext passwords). Keeping track of another login is as simple as adding a new password to my password manager, and that gives me much more control over my digital life than logging into everything with my Google account.

Okay but don't come crying to me when a bunch of your users get hacked because they used the same password on your site as they use on somecrappyforum.io which leaked their password db.
Post reply on HN