Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



Federated identity doesn't replace passwords, it just punts the whole process of authentication to a third party. That third party will still need to authenticate the user somehow, which brings us right back where we started.


But it allows the passwords to be stored by someone who specializes in security.

It'd be nice if everyone who runs a non-trivial website stayed was a security expert, but we're also busy with other aspects of the site.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: