Skip to content

Comment on Password recovery procedure idea

Comments

Do you really want I send my friend address to a website ?

Some users already have difficulties with simple procedure and you want to complicate it. Without talking about issues with old "friend" who will hack you.

I think it is a good thing for an company intranet where you replace friends by collegues. But not for an end-user.

I don't think the meaning of "a Facebook node which may or may not actually be a human person"-friend is intended here; if you use the old-fashioned meaning "someone you know in real life, someone you trust and on whom you can depend" of "friend". Then the fear of "but won't my friend hack me?" is defeated by the very definition of "friend".

Also, the PIN alone isn't sufficient for login - your "frenemy" can only use it to verify your request, not to impersonate you.

Indeed - that was the whole idea. But may be I'm becoming old fashioned ;-)

Also, if something like this gets implemented by a few (or even a single) high profile site being someones 'password buddy' will probably quickly become an accepted, may be even honorable, thing.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.