Hacker News new | ask | show | jobs
by leros 850 days ago
I feel that way about sites that are only email/password. I don't trust them to have good security so I'd much rather use a third party provider. Good to have choice though.
1 comments

I don't really understand this view.

If you're using a unique password per site (ie something generated by your password manager) I don't see how you face any higher risk with the site operator storing a password vs string some arbitrary token from a third party authenticator.

If.
If what?