Hacker News new | ask | show | jobs
by coder543 1524 days ago
> I answered that immediately.

You were conveniently ignoring it in the context where you claimed I was moving the goal posts.

I did not move the goal posts.

> I agree with that idea, but then you said the only way to improve on things was 2FA or SSO which isn't right.

That's an oversimplification of things, at best. I specifically linked to an older comment of mine for those who wanted more detail, and that comment recommended moving away from passwords entirely. You saw what you wanted to see. My summary in this thread was focused on the thread itself, which was discussing how to make password authentication more secure... and the way to do that is to add a second factor. Not security theater like client-side hashing as people were trying to propose higher in the thread.

This discussion is really boring at this point.

1 comments

The context doesn't change your use of the word 'only'. It's not all or nothing. Passwords can be improved and we should use better things than passwords.