Hacker News new | ask | show | jobs
by noduerme 1795 days ago
Think hotel chain with 2-3 employees at a checkin desk, plus a manager on a personal laptop and a franchise owner on a tablet off-site. We have nowhere near that level of control even over front desk machines. Can't even dictate whether they're mac or pc. The software has to do all the heavy lifting of verifying each device by SMS confirmation with the managers, but we have no control over how the machines are set up... I don't think they'd even know how to create multiple user accounts, and if they did, no one would actually log out or follow security protocols anyway.
1 comments

The problem here is your initial recommendations is to "Break autofill for everyone on your website so there's not a security risk in a very few edge cases".

Note all of those edge cases are on computers that should have Auto-fill disabled as part of an IT policy.