Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think a major problem would be one of the most-common use-cases: you're away from your PC, and want to access their site.

To do this, of course, you'd have to get an email sent to that machine. Then, you must login to your email on that same machine to get the PW, and thus the problem: now you have a much greater chance of leaving your email logged in on the 3rd-party machine. Whether it's a friend's laptop or a public terminal (library, airport, etc.) this is not a good thing whatsoever; all you needed to do was to login to a site to post a comment on some silly discussion board, and now you've left the keys to your kingdom in the open.

Further, if there are actual security issues with that box, say it's actively being MitM'd, keylogged, etc. well instead of simply gaining access to your silly forum account, now they will have access to your email.

I think I would flat-out refuse to use any service for these flaws.



It would be great to be able to authorize a login for another machine. I could request a login on any machine and have an email/sms sent to my smartphone and click the link there (alternatively, scan a QR code), and get authorized on the machine initiating the login.

Email/SMS would be an obvious security hole for people who just click "OK" without reading, though. I guess a QR code would be secure anyway.


What if you could get an SMS, or the email on your phone, and type 5 letters into a box on the website?

Normally this would be more work, but if you're away from your email it might be a good alternative..




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: