Hacker News new | past | comments | ask | show | jobs | submit login

I like it. Especially because theoretically it can be mixed with other, conventional authentication schemes, so it can be made completely optional and used at will, just like sites currently mix password + several OAuth providers.

It's pretty much the ideal scheme for all those sites you don't visit regularly (and many of us, despite knowing better, use the same password for...).




Definitely a neat idea. Could also just email them a reusable link except that would leave the credentials in your browser's history unless there is a way to avoid that.


Terrible idea. A reusable link is as bad as emailing a plaintext password and not requiring a reset afterward.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: