Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is clearly a Worse is Better solution. Where the "worse" is the complicated and often not user-visible process involved in getting the login email to them in a timely manner.

That said, I implemented it a while ago, since there's no widely deployed distributed alternative, and as seen with OpenID, attempts to create one will be frustrated by entrenched interests and technical debt.

I still think that Mozilla could have gotten around that problem with Persona if they had built it right into the browser. Pity.



It's more "Less is Better"; today for a password login system you need to have and secure:

1. Password database 2. Password UX 3. Forgot Your Password UX 4. Forgot Your Password one-time-use token via email/SMS

This drops 1 and 2, leaving 3 and 4 as the remaining security footprint.

(I also think that Persona was heading in the right direction and wish it had received better traction.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: