Comment on You don’t need a password. Posterous fail. parentComments−axod16y> "The other fix would be to use an email address that can't be guessed from the blog address. In other words, the email address is the password."You'd still be sending your password in the clear, possibly through other peoples mail servers. Not great security.−tman16yThe perfect is the enemy of the good.There is a trade-off here between security and usability. 99% security is good enough for a lot of purposes and has its place.−infinite8s16yExcept that's more like 10% or even 1% security.−tman16yOh really? I don't think you know what you mean.In point of fact, I just sent myself a very important password in clear text. Hack me.−axod16yThe task for a spammer isn't to hack <USERS> account. It's to hack ANY account.Being able to hack any posterous account is going to be far far easier than trying to hack a particular account.−infinite8s16yExcept that's more like 10% or 1% security.
Comments
> "The other fix would be to use an email address that can't be guessed from the blog address. In other words, the email address is the password."
You'd still be sending your password in the clear, possibly through other peoples mail servers. Not great security.
The perfect is the enemy of the good.
There is a trade-off here between security and usability. 99% security is good enough for a lot of purposes and has its place.
Except that's more like 10% or even 1% security.
Oh really? I don't think you know what you mean.
In point of fact, I just sent myself a very important password in clear text. Hack me.
The task for a spammer isn't to hack <USERS> account. It's to hack ANY account.
Being able to hack any posterous account is going to be far far easier than trying to hack a particular account.
Except that's more like 10% or 1% security.