Hacker News new | ask | show | jobs
by user5994461 2167 days ago
Applications must not be given passwords. Consider that there are hundreds of applications/api/reports in a company, managed by hundreds of developers in different departments.

Passwords would be leaked all over the place (verbose logging, debugging to investigate issues, etc...). That's totally compromising employees/users, as passwords are rarely changed and reused for personal accounts.