Hacker News new | ask | show | jobs
by spaghetti-guy 3419 days ago
Signed up to pose two questions :-

1/ I legitimately do not know a lot of my usernames and passwords. I sign up with a unique email that includes the name of the site (I'm not particularly religious about the format of this and usually end up checking previous email to figure it out). Passwords are saved in Chrome and I mostly don't remember them. I'm sure I am not unique. Where would one stand with this scenario?

2/ Wherever I can, I use a U2F device as a second factor. Could one be compelled to provide this along with the passwords (providing I can remember them)? Where would one stand if the key was unavailable - i.e. lost/left at home? Assuming they have a PC nearby for checking your social media accounts, I'd very much doubt it had it's USB ports enabled so, even if I did provide it, I would suggest they probably couldn't use it. Is there any documented precedent for how this is handled?