Hacker News new | ask | show | jobs
by labcomputer 676 days ago
Weeellll… you’d hope so, but some users may try to autofill a password with the right username, which will inadvertently fill the password too. And now your vendor (Quip or whomever) can potentially see your employee’s passwords. You have to trust them to throw away any password they see for someone from your org.
1 comments

Oh yeah, I'm pretty sure Atlassian used to that, too. So I can understand the reason of "making it easier for users" invoked by people implementing this "two step" login.

But I'd argue this is a different issue than the one of giving out what kind of authentication a given login has.