• BlackLaZoR@lemmy.world
    link
    fedilink
    arrow-up
    5
    arrow-down
    4
    ·
    11 hours ago

    Registration and login should be password less anyway. There’s alredy tech for doing it with cellphone or external hardware key.

    Storing your password hash is just stupid and insecure

    • ExtremeUnicorn@feddit.org
      link
      fedilink
      arrow-up
      5
      arrow-down
      1
      ·
      11 hours ago

      Until you lose your cellphone or hardware key, that is.

      Also, I will not pay any money for a thing just to authenticate myself with.

      • BlackLaZoR@lemmy.world
        link
        fedilink
        arrow-up
        1
        arrow-down
        6
        ·
        11 hours ago

        Until you lose your cellphone or hardware key, that is.

        Same thing if you lose your password database or your master password.

        Also, I will not pay any money for a thing just to authenticate myself with.

        You’ve alredy paid for your cellphone and it is alredy equipped with necessary circutry

        • ExtremeUnicorn@feddit.org
          link
          fedilink
          arrow-up
          1
          ·
          3 hours ago

          By paying money I meant specifically the hardware keys, of which I would also need at least two, just for backup/availability reasons.

          Yes, if I lose my phone and my passords are all just on there, I am in trouble, but I currently don’t handle it that way.

          But if a service relies on specifically my phone (or any other single device) as a factor and it breaks or gets lost, I’m potentially in trouble and I don’t like that.