Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's been a while since I gave two damns about websites keeping passwords in plain text, because nowadays I use a different randomly generated password for each website. If someone compromises a website's database, my password won't work on any other website, and the only website where it works is already under the attacker's control so there's not much additional damage done.

If we made it very easy for everyone to do the same, I think that the problem of insecure storage can be circumvented for the most part, even without moving to a centralized account management system. My proposal is basically to facilitate widespread adoption of password wallets like LastPass. Since such tools are already used by millions of people and does not require much effort on the part of individual websites, I think it has a better chance of success than trying to move everyone to use Persona.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: