Hacker News new | ask | show | jobs
by lxgr 962 days ago
There not even being an extra step is still much safer, no?
1 comments

If I can't get my password thing to autofill on a mobile app (because the mobile app is on a different domain) then it's just annoying because I have to copy and paste over secrets.

That's the wrong thing twice over.

The password app should be as useful to me as a user as it can while still helping me be safe. "Hey, we can't confirm these creds are correct for this app. Do you still want to proceed?"

Or you can add another domain, saving users from easy buttons "yes, phish me anyway" is also useful