authentication

security

Cutting the Gordian Knot of Web Identity

Perhaps you've seen this recent XKCD about password choice? It prompted a spirited debate – even on our very own Security Stack Exchange – about the merits of the argument presented there. Now, to be clear, I'm completely on Randall's side here; I'm all

By Jeff Atwood ·
Comments

authentication

Removing The Login Barrier

Dare Obasanjo's May 26th thoughts on the facebook platform contained a number of links to the Facebook API documentation. At the time, clicking through to any of the Facebook API links resulted in a login dialog: It struck me as incredibly odd that I had to login just

By Jeff Atwood ·
Comments

security

What You Have, What You Know, What You Are

I'm no fan of the classic login/password scheme. I can barely remember any of the zillion logins and passwords I have. More often than not, I end up using the "forgot password" link. Which means, in effect, that my email account is my global password.

By Jeff Atwood ·
Comments

password management

The Login Explosion

I have fifty online logins, and I can't remember any of them. What's my password? I can't use the same password for every website. That's not secure. So every password is unique and specific to that website. And what's my

By Jeff Atwood ·
Comments