Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A magic link is just a form of 2FA. And the reason not to make 2FA mandatory isn't about engineering costs -- they'd already built it. It's because a lot of users don't like it. I personally despise sites that require a magic link rather than a password, because it takes me 30s to log in instead of 1s.

There are lots of commenters here on HN in this story saying they don't think sites should make 2FA mandatory. There are lots of usability problems with 2FA as well -- if you lose a device or when traveling.

You're basically saying that sites that allow you to log in with just a password, if you choose, shouldn't be allowed to exist. That seems unreasonable to me.



> You're basically saying that sites that allow you to log in with just a password, if you choose, shouldn't be allowed to exist. That seems unreasonable to me.

I'm saying sites that host information of value, such as genetic information, should not be allowed to support login with just a password. That seems reasonable to me, and a regulatory gap to be closed. If you don't want to use MFA or other secure auth systems on Reddit or Twitter, by all means, I'd agree that secure auth for low value systems might be overly burdensome to a user population. There are well worn paths if you lose MFA (remote identity proofing, mailing an OTP to known addresses, dinging a credit card $1, etc) that are all reasonable and affordable to implement.

Is your argument that the data 23andme hosts is not of value or sensitive and it should not matter if their security story is lacking ("just passwords are fine, yolo")?

EDIT: I think we fundamentally disagree on the issue.


> such as genetic information, should not be allowed to support login with just a password. That seems reasonable to me

But that isn't obviously reasonable to me, that we need a law for that.

What if I don't think a bunch of estimates based on a bunch of my gene readings is all that valuable? Why not let me choose to use just a password?

But if I do think it's super valuable, then I can use 2FA. (And also obviously choose not to share any of my information with anyone else on the site.)

Why should it be the government's job to remove that choice from me?


How about a middle ground, where if I set up MFA on my account, I automatically disable the access from "distant relative" who haven't setup MFA, even if I want to share my data with them. Because fundamentally this incident is not serious if such transitive access was not employed in the first place.

And since this is a specific access pattern for 23andme, I agree we shouldn't involve government here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: