Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While it bothers me as well, this flow isn't too common. It's usually only used for MVPs because of how quick and easy it is to set up.

What I'm more bothered about is that sites who use traditional username/email and password increasingly don't actually seem to care about my password. They always require 2FA, email or phone, and I don't have a choice. Username + password simply isn't good enough for these people anymore.



I am seeing this much more frequently in services I use. Rarely, they have a small option that says "use password instead".

I agree that it's pretty frustrating, since I have strong passwords in my password manager. Like another poster, I assume its used because it provides better security for the majority.


A lot of companies have started doing this because a compromised account can be used to attack the service (logged in sessions avoid rate limits) or other users (spam). They aren't necessarily trying to protect you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: