Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Npm can't force people to use password manager


Nor does TOTP+password lock you to one authentication provider indefinitely. Tradeoffs :)


You can always register a new passkey with the site if you want to switch authentication providers, can’t you?


Yeah, I guess that'd work if I had a couple of accounts, but since there a bunch of them, I really need proper import/export to feel comfortable with moving to it. I just know I'd punt the task of migrating everything if I have to go account-by-account to migrate away.

Considering that today it'd add work for me today, and future work, with no additional security benefits compared to my current approach, it just don't seem worth it.


I've got passkeys from multiple "authentication providers" available on all of my devices. This isn't a tradeoff.


You can if you just force passwords longer than people can memorize or even want to write down (assigned 24+ characters)


It's just gonna be on a sticky note hanging on the screen or under keyboard


careless people just copy paste those




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: