Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't get it. At all. The only purpose of the password is to authenticate you against your account. Why would you refuse to use it for this? It's the point of a password that you submit it.¹ Oh yeah. Because you don't trust the guy on the telephone. He could easily hijack you account and do nasty stuff. 1) He could do if he wanted if you didn't tell him 2) You're not trusting him/her? Why are you doing any business with a company you don't trust?

Or is the point that somebody could wiretap you? Get off your tin foil hat and think about keyloggers.

¹) Or do a challenge response. It does not matter. It's a shared secret.



The point is simply that established practice is to never share passwords, and this eschews that practice. I can see your point, but they have a variety of other data they could use to verify who you are. This is about the worst idea.


Actually, no it's way above better than other ways they could verify your identity. Did you not read account of the Wired reporter who had his online identity stolen and wiped because companies used easily obtainable information about the person to identify the person's identity? If they had used a password instead it never would have happened.

I don't understand what your issue is with telling them the password? Just change it to something random and change it back after if it's not something you are comfortable sharing or saying out loud. It may personally offend you, but t's certainly not a bad practice.


No, that's not true at all. Every time you log in you share your password. That's the point of a password. (unless it's some fancy public/private key stuff).




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: