Live data from Hacker News

A lingering farewell to the username

api.slack.com

71–80 of 94 posts

Re: A lingering farewell to the username

#71

I think they're missing the point, Twitter got the display name / username dichotomy right: Display Name: what everyone sees next to your username, no guarantees that you don't change it every 5 minutes though... username: something short you choose and change rarely, can be cool, memorable, fun, and quite creative, always unique [Real Name: who cares, often necessary for work tools even though email ought to be enou…

Twitter has some problems too. People do change their username, and every time they do, all previous tweets mentioning them by @username lead to dead ends.

If they do (I haven't verified if you're right) then that's an implementation issue. Twitters API returns rich information about every mention that shows they very well could store an association to the internal user id if they want to.

But it may very well be for good reason. E.g. lets say an account is taken over by someone who changes the account into something suitably offensive after obtaining a lot of mentions. It would seem that treating a change as basically "this is a new account now" is the safest alternative in some respects.

Re: A lingering farewell to the username

#72
post #52

Earlier quoted context omitted.

You don't. You pull up your password on your phone and type it in manually onto the computer.

> You pull up your password on your phone and type it in manually onto the computer. Sounds like someone isn't using a 100-character randomly generated password.

With mixed-case letters and digits, all you need are 22 characters.

A 128-bit security margin is considered good enough currently; a 62-character alphabet (26 lowercase, 26 uppercase, 10 digits) provides 5.95 potential bits of entropy per character; thus a 21.50-character password would provide 128 bits. You can't have a fractional character, so … 22 characters.

Typing 'tgcSq08O2fEZ5hcZk3Gvgk' in from a screen is easy enough, although not something I'd want to do every day.

Re: A lingering farewell to the username

#73
post #52

Earlier quoted context omitted.

You don't. You pull up your password on your phone and type it in manually onto the computer.

> You pull up your password on your phone and type it in manually onto the computer. Sounds like someone isn't using a 100-character randomly generated password.

Maybe try InputStick then?

Though I think 100 random characters is well beyond the point where you're no longer significantly increasing security by adding more characters. You can easily get 130+ bits of entropy with only 20 characters, and even for a ridiculously weak hashing algorithm like MD4 that'd be enough to withstand the entire combined strength of the Bitcoin mining network attacking your password for well over a billion years.

Re: A lingering farewell to the username

#74
post #13

When this started rolling out it caused havoc for us. Without any warning that this was happening half of the people in our org got their display_name set to their full name, and the other half got their handle. For no apparent reason. Within the technology parts of our org everyone knows each other by handle, and we still let people pick their own handle when they join. It's even pretty common to only know people by…

Some more security minded folks may have noticed that the first revision of this "feature" allowed 'slackbot' as a display name, as well as changing the icon to match.

Thankfully they've fixed that now but yeesh.

Re: A lingering farewell to the username

#75
post #40

Earlier quoted context omitted.

Does he avoid banks, too? I don't really see how his scatter-brained approach to login management is any less of a problem there, or on literally any other system that uses an email as a username or a password recovery mechanism.

I'm all for using a password manager. I also think it's not user-friendly for a single application to force one to use multiple email addresses. It's unnecessarily confusing and annoying.

Slack doesn't require you to use multiple email addresses. I log into most of my slack teams with a single email address - to log into Slack, you need a unique (slack domain + email address) combination, not a unique email address.

Re: A lingering farewell to the username

#77
post #33

Earlier quoted context omitted.

I think the point is that he's avoiding the product rather than change his process, and that he's hardly the only one.

Does he avoid banks, too? I don't really see how his scatter-brained approach to login management is any less of a problem there, or on literally any other system that uses an email as a username or a password recovery mechanism.

I think most people would avoid banks if they had the option. Slack is not something that came along thanks to the Federal Reserve Act in 1913

Re: A lingering farewell to the username

#78

Slack's authentication flow is the dumbest I've ever had the misfortune of using. I'm a member of multiple Slack organizations, and it needs one login per organization . I can't just have a single email address and join whatever org I want, I have to remember which email address I used for each one, otherwise I can't log in! I have multiple email addresses and don't use a specific one every time, so I have managed to…

"irc is dumb! every server requires a different nick, wth?"

"IRC is just multiplayer notepad"

Re: A lingering farewell to the username

#79
post #14
post #5

I have no idea what the product manager was thinking here... Can someone elaborate why this "feature" - which implies potentially a lot of confusion - benefits most users?

So I think it’s because they’re introducing shared channels between multiple teams/workspaces. As a result usernames can clash.

Wow, "it's more convenient for us to scrap usernames rather than re-think our system" ... I love you Slack, and I also don't understand how you are where you are.

Re: A lingering farewell to the username

#80
post #53

Earlier quoted context omitted.

Yeah, I had that problem with some US govt website when applying for ESTA. I have since fixed the problem : My email is *@roblab.la, and I just put whatever the org's name as the username part of my email. So far it has worked basically everywhere, except on aliexpress, where they disallow aliexpress@EMAIL_DOMAIN. Probably to avoid people posing as staff >_>'.

I tried that too 15 years ago, but had to stop after a year. It turns out many spammers send mails to random usernames

So far spam hasn't been a problem (I get none). I have spamassassin set up, but it doesn't filter anything for now, just scores stuff. If it ever gets to the point where I get too much spam, I'll probably start to filter it.
Post reply on HN