Hacker News new | ask | show | jobs
by mingus68040 4006 days ago
#1. That's true, but it would still be more of a barrier to creating secondary troll accounts than what reddit has now.

#3. The idea is to tie the account a specific device (such as an iPhone), by generating a unique signature in the app. For this to be enforceable, logins outside the app cannot be permitted -- otherwise signatures can be forged.

1 comments

Fair points.

#1. I still think #2 is a more important barrier, but I don't see a huge downside with this either. You didn't explicitly say this, but I think you're making the point that troll accounts can never be completely eradicated. But you can make it significantly less convenient for them, while minimally inconveniencing most legitimate users.

#3. I get the general idea, but I don't see how it's substantially more secure than requiring 2FA. I mean, GMail, Dropbox, AWS, etc., seem to think 2FA is sufficiently secure for very sensitive data, and they allow interacting through the web browser. Plus, at the end of the day, you'll need some mechanism for adding new devices, which will effectively work like 2FA – I presume.