Hacker News new | ask | show | jobs
by KludgeShySir 3 days ago
I'm begging, please let me use password "asdfasdf" on throwaway accounts. I accept full responsibility for the fallout.

Seriously, many web admins need to hear this message: "Chill. Your site is not that important."

4 comments

It’s always interesting to see how fast someone takes a proposal and takes it to some ridiculous extreme.

Websites don’t know your account is a throwaway one, and making an exception for those accounts doesn’t make sense anyway.

Saying “ I accept full responsibility for the fallout” obviously doesn’t work on a large scale and here exceptions don’t make sense either.

Just use a password manager that generates and fills your passwords, and never worry about your passwords for those sites. Don’t tell web admins to drop basic security measures because you don’t know how to manage passwords.

I'll repeat what GP wrote:

> Seriously, many web admins need to hear this message: "Chill. Your site is not that important."

No site is important until it is, but by then it's too late to overhaul your security architecture.
No, the site doesn't become important if it wasn't from the start. This is not conditioned on individual use cases. Government sites, your bank, your healthcare provider - they have the important sites. Your e-mail provider is important too, because by accident of Internet history, your e-mail is your backup key to everything in your digital life.

Beyond those, nothing is that important. Your random e-commerce site or discussion board are not that important. Neither is your ISP or the service where you fix your appliances (or phones). And especially not the random fly-by-night startups that want you to register before you test their "game changing" SaaS.

The sad irony is, the smaller and less important the site, the more stringent security measures they tend to deploy, because security theater is trendy nowadays. 2FA is so 2025, if you're not demanding passkeys, you're a dinosaur.

(A good heuristic to use: if your site has harder security than your government's core services, especially when it comes to recovering access, it's worth asking whether there's any actually sensible reason for it.)

Your site is non trivial.
You have a throwaway account?

Can't have that! We wouldn't have any data to sell!

We need ID, email verification address, phone number, and a selfie of yourself holding a handwritten sign saying, "I love <useless company #7983>" now.

And you have to do a captcha at every step. Click on every crosswalk, sucker.

Sometimes companies assume my password has been leaked and keep making me change it over and over again. Eventually, I end up forgetting my own password. It’s really frustrating.
> I accept full responsibility for the fallout.

But you can't - when it includes damage to the provider e.g. brand tarnishing.

A lot of user-access "security" is for the benefit of the provider, not the user.