Skip to content

Ask HN: What Has Happened to Authentication?

3 pointsyoz-y1 comment
On HN

So in the past we had usernames and passwords. Later we ditched the usernames for emails (it's harder to forget your email). Then we added SMS, and later OTP for security.

All mail + password + OTP works incredibly well, is secure and plays great with password managers.

Then something happened.

Because of single sign on, we could no longer have password field on the same page as the email.

Because of passkeys, now any login screen on a computer takes ages to go through. All french banks use a fancy keyboard with scrambled buttons, but then force you to have an 8 digit password...

And more recently, services ditch all login methods for a daily dose of "we've sent you a magic link that will keep you logged in for a day".

Claude authentication is so user hostile that I am now just waiting for my subscription to run out to ditch it, others have caught up anyway.

Does anybody working actively on security have an insight on how we got here? Are there any security benefits? Are there any user studies showing that what we currently use is somehow better?

Comments

Capitalism is user-hostile, deal with it.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.