Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Neither of those problems (lost key, compromised key) are anything new. Why wouldn't sites just handle them the same way they currently handle revoking/resetting passwords?


Because the current way sucks.

99% of the websites (I have accounts on) rely on my email for recovery and revocation. But my inbox is not an impenetrable fortress, it's a communication channel; every device I own has access to it, and could be used as a backdoor to my entire digital life.

Then there's the risk of the third-party (Google banning me, being hacked, subpoena'd, etc), the privacy factor (see the Ashley Madison leaks), the often custom code implemented by each website...


> every device I own is has access to it

and this sucks. Why can't I use my google account with my tablet without it automatically getting access to gmail sync?


So we can't improve the current situation at all until we solve all the problems?


Good point. I think these specific problems were somewhat solved by other protocols, such as SQRL, but you are absolutely right, FIDO + email is much better than password + email.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: