Hacker News new | ask | show | jobs
by mtlogstdo 2502 days ago
Imagine all you have is a password, and I come along to register, attempting to set my password to "hunter2". Turns out someone else has already used this. Do you allow me to continue or tell me the password is already in use? If its in use - great, I'll just log in using that other guys account!

Of course, you could let the site specify the password, which would work if they're long and random. But social security numbers are neither of those.

1 comments

Nobody said they should let you choose your own passwords. We were comparing with SSNs, which are assigned to you, not chosen by you. You'd do the same with such passwords. And nobody claimed SSNs are appropriate passwords either.
>And nobody claimed SSNs are appropriate passwords either.

Except for the US government, and most banks, medical providers, and cell phone companies.