Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have a friend who can't actually tell you her passwords, because she doesn't know them. She just resets them every time she needs to log in to some site.


I wouldn't like it myself because of the extra steps to reset each time, but it does make sense. "Can you access email sent to this address" is probably a reasonable authentication challenge for a lot of purposes. (It might even be phishing resistant...)


The email she uses is the main email address from her ISP, so she can also reset it by requesting a reset code by text (or, at worst if she also loses her phone, by going to a store and showing her ID).

After thinking about it, the only real problem I found was indeed the extra hassle. I stopped trying to convert her to a password manager after that.


as moronic as that sounds, i know people just like this as well.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: