Hacker News new | ask | show | jobs
by kfriede 1964 days ago
Would an alternative be to offer auto-generated usernames that you have one-shot to generate a password for and if you lose that password you're gone? Something like opposite-dwindling-zodiac, casino-smile-widget, or creative-crumpled-dismiss?

If you choose to add a phone number as a recovery (and for contact finding) that's your optional choice.

1 comments

There absolutely are mitigations from a technical standpoint, some with privacy trade-offs and some with UI trade-offs. But the key is to have those mitigations in place before you launch a feature with potential attack vectors.

Moxie's statement in that article claims they have no plans to address it.