(评论)
(comments)

原始链接: https://news.ycombinator.com/item?id=43397117

Hacker News 的一个帖子讨论了 Cloudflare 关于广泛密码复用和泄露的文章。用户表达了对密码管理的沮丧,并渴望更轻松、更安全的替代方案。 Rucadi 建议在设备或外部加密设备上使用加密密钥进行登录,并结合生物识别技术进行本地访问,以及一个超级安全的用于紧急情况的一次性密码。Dsego 想要将数字凭证与可验证身份绑定以进行恢复,类似于银行账户重置,并将其与 Google 账户恢复的困难形成对比。 Esher 质疑与 Cloudflare 共享密码的明智性。Bstsb 解释说 Cloudflare 的密码泄露检查功能不会存储明文密码。Otabdeveloper4 表示更愿意处理泄露的后果,而不是密码管理的麻烦。


原文
Hacker News new | past | comments | ask | show | jobs | submit login
Password reuse is rampant: nearly half of observed user logins are compromised (cloudflare.com)
10 points by cassianoleal 1 hour ago | hide | past | favorite | 5 comments










Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an external crypto-device to login was easier and more common.

For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.



I want to be able to tie digital credentials to my identity so if they are compromised or I loose access I can recover them by providing my country's issued ID documents. Similar how I do with my bank app, I go to the bank, show my ID, sign some forms and reset all the creds. I don't have to fear loosing access. On the other hand if I loose my google account I'm screwed, all my other services depend on either my email address or google 2fa keys to prove my identity.


Shall we really share our passwords with Cloudflare?


"As part of our Application Security offering, we offer a free feature that checks if a password has been leaked in a known data breach of another service or application on the Internet. When we perform these checks, Cloudflare does not access or store plaintext end user passwords."

https://developers.cloudflare.com/waf/detections/leaked-cred...



Frankly, I'd rather deal with the consequences of being compromised than with the problems of memorizing and recovering passwords.






Join us for AI Startup School this June 16-17 in San Francisco!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact



Search:
联系我们 contact @ memedata.com