Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, to be fair, it wouldn't be all that complex if we just had one standard instead of many many many to learn. I don't find OAuth2 as implemented by most all that complex, and I didn't really find OAuth1 all that bad either.

The web UI for persona, on the other hand...

Who on earth thought it was a good idea to have a two step for username THEN password!?



Microsoft does the same thing with many of their logins. You put in your user ID, and it uses that to know what server is going to authenticate you and forwards you to it.


> Who on earth thought it was a good idea to have a two step for username THEN password!?

I haven't used Persona, but maybe this is because not all users use passwords? Sometimes you use AD authentication, or token generators, or ...


Sure. But what percentage of users would that be? Single digits?


> Who on earth thought it was a good idea to have a two step for username THEN password!?

Google, as of a while ago.

Persona at least had a good reason for it, with not all users needing to enter a password.


Perhaps, but it seemed to do a pretty poor job of remembering me...

At least with Google, despite them being a pretty poor example of good auth UX, you only ever have to type in your password (+ 2fa code etc)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: