Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I keep asking users about this login process and passphrase instead of password. Most users seem to feel suspicious of the email login because most users have already been trained to not entirely trust their email. I don't think that this could become an accepted authentication method simply because of that


Regardless of whether this will be accepted, users need to be retrained. Any site that offers a password reset via email already effectively lets you login via email. Users should be aware of this so they can be more careful with their email (picking a decent password, ensuring they logout on public computers, etc).

IMHO everyone should be using two-factor authentication for their email.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: