Hacker News new | ask | show | jobs
by bluesnowmonkey 5096 days ago
Email+password. As a user with a password manager (LastPass), I can log in with one click, use a unique password everywhere, and never forget a password. Can't beat it in terms of usability.

From the developer's perspective, there's a bit of boilerplate to be done, but it's nice to own the data and not rely on third party platforms.

I think there's an unfulfilled need for identity management by password managers. Why do I have to enter the same information everywhere? It would be nice to be able to click a "Create Account" button on a website and have it get my name, email, and new password from the LastPass plugin over a standard protocol.

3 comments

I agree - I don't use a password manager, but I find this to be the best option. I would suggest using email vs having the user create a username (email is always unique, but when you have a common name and your username is sometimes taken, you have to choose a secondary or tertiary username, which can get confusing).

I don't have any problems wit Facebook/Twitter logins, but I would suggest holding back on the permissions requests. If I see that a website wants to have the ability to post as me or invite friends as me, etc., I will think twice about accepting. If they just want to access my name/email for auth reasons, I'm usually happy to do so.

I like OpenID, but am not sure if it is as widespread among the average user (especially vs Facebook or Twitter) an having that as the only login option may shy people away a bit.

Haven't used BrowserID, so personally I wouldn't use it. I don't know the numbers on this one, but you may get a specific demographic of users if you go with this one.

Thanks! I didn't think about LastPass, but since the website will be targeted (mostly) towards a hacker crowd it makes sense that many of the users will use a password manager like LastPass. I'm not a LastPass user myself but I guess that takes away a bit of the hurdle from a user's point of view.
Somehow, I suspect that someone would build a website (or three) that would automatically create a new account for you just to collect your information.