Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Most people want a way to recover their account if they lose those creds, especially when you ask them once they’ve lost their creds.

It’s also a rudimentary PoW system against bots. And people who don’t want to share their email can use a temp email service, so it’s no skin off their back.



> And people who don’t want to share their email can use a temp email service, so it’s no skin off their back.

That seems to be a better option for bots than for actual users: if you care about the account, you probably would not want to make its password resettable via a service like that. Or even via a regular email provider you do not trust, and those could easily be the only kind available.


So make it optional. I've seen sites like that.

Bots have no trouble signing up with @mybotfarm.example addresses.


Ultimately this is akin to password requirements. They are a bother but the average user is just much too careless to be trusted with their own security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: