Hacker News new | ask | show | jobs
by cevaris 4400 days ago
Wouldnt the unique identifier or Auth token be the password? Sure it is more convenient for the User not having to remember there password, but it is not necessarily more secure.
1 comments

I think ideally it would be a temporary auth token, only used to get the session created.