• vzq@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    14
    arrow-down
    1
    ·
    1 year ago

    Passwords, as in user chosen secrets used to prove identity, are a really bad idea in general. Turns out, people are crappy at coming up with stuff that is hard to guess. They are also crappy at remembering things that are hard to guess. That’s why every website these days wants to SMS you a code or makes you use an Authenticator.

    Thankfully people are catching on, and secure passwordless sign in is gaining ground rapidly.

    • Call me Lenny/Leni@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      3
      ·
      1 year ago

      I’m surprised no place uses IP addresses anymore to authenticate (I was around when Postopia did or whatever that candy themed game place was). Many IP-ban when it comes to identifying rulebreakers, you’d think they’d IP-authenticate too.

      • mackwinston@feddit.uk
        link
        fedilink
        arrow-up
        4
        ·
        1 year ago

        Carrier grade NAT. For instance, on our local mobile phone network, thousands of handsets will have the same public IP address.

      • vzq@lemmy.blahaj.zone
        link
        fedilink
        arrow-up
        4
        ·
        1 year ago

        All major services do risk based authentication these days. I’m fairly certain network address factors into the risk calculations.