Stop Doing Passwords
if other people weren’t supposed to be in your account, why does the server it’s on keep getting breached?
Discussion
Stop Doing Passwords
if other people weren’t supposed to be in your account, why does the server it’s on keep getting breached?
look at what the Password Industrial Complex has been demanding your Respect for this entire time (these are real inconveniences dreamt up by real sweaty guys in meetings):
- fascist slop password managers (almost all of them)
- registration forms that don’t allow automatic input and require a complex password, and then a year later you get the email telling you the password leaked online cause they stored it unhashed in mongodb or whatever
- passwords suck, let’s make every login a “forgot password” link with the associated email spam and jank and incredible slowness
- getting dark patterned into using a passkey, a system that has so much Discourse online that I’m pretty sure it has no chance of being good
- your second factor is just your first factor but less convenient
- did you accidentally click yes on the passkey popup yet? come onnnnnnn
they have played us for absolute fools
don’t post in this thread about how actually passkeys are really good if you never change phones
don’t ask me “what should we do instead”, we live in a world where we can’t make a good password manager for some reason without fucking it up
if either of these things make you angry, go make a password manager that’s worth a damn
it’s uhh notable that password managers all have to do this weird fucking dance where they manage your clipboard and try to auto-insert just the right password into just the right field on the page, and absolutely none of the android vendors or apple offer the option to just fucking emulate a keyboard and have your phone fill in passwords for the rest of your devices
I’m very certain there’s a deranged infosec reason why my allegedly secure phone can’t act as a password box for another device, and I’m pretty sure it’s made up by the same deranged infosec guys who insist localhost needs https and a certificate or else your browser will silently disable a bunch of shit
I know better than to ask the graphene devs for this, it’d be too handy
You need to log in to see that page.