Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Easy: everybody authenticate with Facebook Connect, then we just have a single location and storage mechanism to secure.


As silly as it is, it's what I'm doing for a lot of my non-essential sites. Being able to see who I've signed up with is also nice, as I'm sure I'm signed up to a whole host of sites that I have zero memory of.

That, and Facebook supports two factor authentication and (hopefully) isn't leaving their pw db as unsalted md5...


Ha-ha. And nothing goes wrong.


s/secure/crack.


Also one password to change, though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: