logoalt Hacker News

CPLXtoday at 12:17 AM5 repliesview on HN

> Clickable links sent in email are more secure than passwords so I'll stop supporting passwords and instead rely on email delivery of a link for all logins

God, I fucking hate that.

I have a fucking password manager, I have various machines and things open. Just let me fucking log in.

If anyone is reading this who is in charge of the internet please stop doing this.


Replies

roygbiv2today at 12:46 AM

I seem to spend half my life logging into thing's, confirming 2fa,confirming biometric data. Then when I go back to the first thing it's timed out and I have to sign in again.

paradox460today at 7:53 AM

I'll heap email and sms based otp into that

I have many ways to generate totp codes. All of them are vastly more convenient than sending me an email or sms

anon7000today at 1:04 AM

So agreed. It’s fucking crazy. Password manager is so much easier and more secure. If you do this dumb email or SMS OTP flow, at LEAST support passkeys for my password manager!

It’s wild that they’re like “it’s more secure to not have a password” and then choose two unencrypted delivery mechanisms for the very short OTP.

Sure, people who reuse passwords are not secure. And fair, I guess it’s a tragedy of the commons. But at least continue supporting it and make it dead simple for password managers if you actually care bout security

show 1 reply
denkmoontoday at 12:30 AM

The people in charge of the internet are "cybersecurity" "professionals" who can't even follow NIST guidance.

show 3 replies
Terr_today at 1:48 AM

There's a landlord/apartment portal where the whole login process has changed to be:

1. Enter username (e.g. an email)

2. Choose from either email or SMS on file

3. Enter the code you got somehow through the respective unencrypted channel

Given that this same site is involved with bank-account details for payment, I am concerned...

show 1 reply