Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I would much rather run my own identity provider where I can control exactly what it takes to authenticate (multi-factor, etc.) and only need to keep that secure (which is a lot easier, because it can be some locked down server) instead of needing to keep my passwords on my devices I carry around.

One of the major benefits of identity providers is that we eliminate the need for a million passwords for all the sites you use, the only thing this does is provide a perhaps more convenient way of living with the problem instead of a solution to eliminate the problem.

Also, http://xkcd.com/927/



Sure, but one of the major drawbacks of identity providers is that the vast majority of websites will never integrate with them, period. We need a solution for those websites, too, and what I'm proposing is one attempt at finding such a solution without telling every website owner to rewrite code.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: