Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Login PIN by email is a much better pattern along the same lines. Forcing a specific, impossible to remember string on the user is weirdly hostile.

If you want to avoid a password, just email the user a PIN every time they need to login. This works great for apps which don’t need high security.



It doesn't work great, with a password I have a single shortcut to autofill from the password manager

With a stupid email login I have to do many more steps (and email isn't 100% reliably immediate)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: