Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think it's the people who pick bad passwords that are making login flows worse. Bad actors are the reason we have passwords in the first place, yes, but authentication still shouldn't be as bad an experience as it is today. As it turns out, after thirty years of internet access, people just suck at picking a good password.

When I generate random passwords, people complain that they're unreadable. When I ask them why the password they need to enter once every two years would need to be readable, they just shrug. When I bring up the ability to save passwords to their devices using a password manager or their browser, they say they're "not into IT" and ignore any advice beyond that. Then they change their passwords to Welcome2024!, and that's why we have to make things more complicated. I don't care about most random accounts, but the Welcom2024! people are the ones safeguarding personal data, medical information, and so much more, and if they don't care, you have to force them to use computers responsibly.

Most websites would be perfectly fine with just a username and a randomly generated password. Even eBay or banks, if we're talking about <€100 worth of transactions/day. 2FA is a workaround only very few, very important services should actually need.

However, in real life, we can't do that, because when the Welcome2024! people get their accounts taken over, their digital wallets drained, their credit cards emptied out, and their life ruined by people on another continent, it's always the websites' fault. People love to say "Google/eBay/PayPal/my bank should've prevented this" but when these services take steps to prevent that stuff, they get mad that everything gets so complicated.

Bad actors will always cause things to be worse, but the general apathy the general public has to digital safety is the reason why it's _this_ bad.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: