Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm so fucking sick of places enforcing that shit. Not all of us have shit passwords.


There is still a ceiling to how secure a password can be which 2FA solutions will generally beat (mainly by the secret not being spread as far when used, such as keyloggers, window focus mishaps, or simply being sent to the server verifying it).


At least they are not 100% head-in-ass sesoority yet and still allow to at least self-host to disable that crap.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: