|
|
|
|
|
by mnw21cam
4440 days ago
|
|
Correct horse battery staple.
http://xkcd.com/936/ We are told to not re-use passwords. This is not helped by every single shopping web site out there requiring an account (and therefore a password) in order to buy something. Fair enough for big sites like Amazon - I'm actually likely to come back at some time in the future, although I dislike the way it tries to store my card number each time. On most sites, requiring me to create an account discourages me from shopping there. I'm not likely to come back unless I suddenly have a burning need for another obscure once-in-a-lifetime widget, so why do I need an account? If I do come back, you still only need my card number and a delivery address. As it stands, the sheer number of accounts that I have means that I invariably set an impossible to remember password and immediately forget it, relying on the password reset mechanism. This is not ideal. |
|
Password reset without the password. If my email account is compromised then everything is screwed, but with password-reset emails that was already true.
Of course, this is potentially vulnerable to abuse... but again, password-reset emails have the same problem.