Hacker News new | ask | show | jobs
by charlie0 1438 days ago
The issue with pushing this responsibility onto companies if that they can only help with reactive measures. They can't easily take a proactive approach. How does a company prove someone is not who they say they are when all they require is an email and maybe a name to create an account?

At best, they can make it slightly harder to impersonate a user by requiring MFA and detecting duplicate accounts (ie, accounts using the same picture). I think stuff like this will only get worse over time.