logoalt Hacker News

jasongi • yesterday at 3:19 PM • 0 replies • view on HN

It's not about cloud environments. Basically every ToS ever forbids you from disclosing your password to someone else or another entity. Even when you use a cloud-synced password manager, the whole security posture relies on that data being encrypted the entire time and never read in the cloud.

The worst security faux pas of companies is storing user passwords - because the most common source of account breaches is via credential stuffing, where they get hacked, have their user base's passwords stolen and tried on other websites. The remedy being... not to store passwords, only salted, secure hashes.

Muse sounds like a disaster - your credentials for other sites are floating around on their servers, with the capability of being decrypted. Maybe if sites decided to offer a form of auth tied to the agent that could be revoked in bulk in the event of a breach it might be a ok, but this is crazy.