Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Backup with 3rd party == giving up access to 3rd party. #1 principle of this protocol is not giving up access, at least by default. You are free to email your password to yourself, write it on a note, but it will never offer to send your password on your phone number. We live in a hostile world.

> Does it mean I can never log into the sights using the same account ever again?

It's up to the websites, they could use your email for reset + lots of personal info you have about account activity.



Right. My point was only that most people may want a lost-password fallback; this scheme doesn't prevent implementers from providing that, so it's not really a big deal.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: