Hacker Newsnew | past | comments | ask | show | jobs | submit | rdsubhas's commentslogin

Your article was well worth the read. Thank you for that. It's merely a HN trend where lazy people who can't read an article bad-mouth it as AI. You'll find the lazy AI comment in every article's top first or second comment now. Don't bother justifying yourself, keep it up and keep writing.

Here we go again. Commenter doesn't read an article because it doesn't fit their style. Immediately bad-mouths it as AI.

Edit: typo


> what I'd REALLY F'IN LOVE to see go away is the passwordless/magic link auth flow

This seems really naive? That's the only flow that's at the basis if you get locked out. What else, do you put people on the phone to verify people by asking their name and date of birth? That's even worse!


I think they're referring to sites where that is the only way to sign in, which I have seen a few of. Basically you can never register a password or passkey, every sign in requires going to your email and waiting for the link to arrive.

I've seen Slack and Claude doing this among others, it's turned into one of my leading red flags for untrustworthyness.

I get the idea. If email links are secure enough to use for password resets, just do that every time. Then you eliminate a whole category of password attacks.

But it’s definitely annoying for a frequently used service.


Maybe this gets us closer to some idea of email being a more protected digital service, that has some legal guarantees?

Putting the potential negatives under the rug for a second…

I would be nice to have email that (1) you can’t get locked out of arbitrarily, (2) acts similarly to US mailbox (in its protections and universal service), (3) acts as an identity

Is this a bad idea?


Only if it's run by the state and free for every citizen. Forcing more bureaucracy on email providers will just make everything more centralized under Google and Microsoft.

It should be a mailbox with E2E encryption where the keys are stored on your ID card. Backups stay on secure servers that are legally protected from anyone including the police and only given out when you're getting a new ID at a government service center, encrypted with the cards public key so a hacker in the card issuing system can't steal it.

Every user gets a persistent address used as their identity, and any number of anonymous ones. Locking someone out would be both illegal and inconvenient for the government if all their official business is going through the mailbox.


Horrible idea. This will require every email vendor to certify with every country they provide service to that wants to do something like this, which will pretty much kill any small/indie email hosting providers.

I'd much rather have stricter legislation around password resets built into existing reg frameworks like PCI or HIPAA. If you store a form of payment or PII with a provider, then some form of human verification should be needed to perform a password reset.


A German neighborhood social network uses this, and I prefer this over all other sites I visit that have passwords.

I only need a new login link when I switch to a new browser or device, so it's not really annoying at all.


I do it for small projects with about 10 infrequent users. They would ask me to reset it almost every time anyway.

Though next time I'll probably try oidc if I can find a common provider that isn't a hassle


Untrustworthy... yes.

I get more annoyed by the timeout it adds. Logging in 10 years ago? A thing of seconds.

Logging in today? Either magic links through mail (delivered to you within the next 30min thanks to graylisting or spam filters) or a login flow with requires 5 dialogs and 5 confirmation of "no, just log me in".


I think all Shopify sites also do it now? I'm migrating password managers and have been going over all of the old accounts I've had. Several sites that use Shopify for their stores now just don't accept any kind of a password.

I despise that too. One website (was it walmart?) gives me option to use that or a password, I select password and after entering it it tells me that it needs to verify my e-mail "for security" where I get link or code to log in.

At that point what's the point of password? Just an optional extra step?


Correct; that's what I'm talking about. Sites that send you a link first before letting you enter a password (Spotify) are also on my bad list.

I mean, if the session token basically never expires it's kind of fine?

For services that have your PII or payments details, yeah, that should be the only way to do a reset. Super inconvenient but much less so than dealing with stolen identity or credit cards.

It's the stupidity of Service Providers to adopt passkeys in the first place.

As a service provider myself, I've evaluated and said "Nah" to passkeys - because it's simply increased Customer Service contacts I have to invest in, whenever a user changes or loses devices, or any of the hundreds of ways Passkeys are not portable.

And guess what, the Tech companies pushing this have zero liability for user login support or security breaches. It's always me. There is no need for me to work hard and spend CS contacts, to wall off my users to the OS or Browser vendor.

I'll simply do passwordless Email or SMS 2FA / Magic Links and own my users without the overhead of Customer contacts, thank you.


I understand many passkey complaints but not this one. Why, for you as a service provider, are passkeys not just better (or at least equivalent to) passwords? You collect and verify an email address at signup and the account can be recovered in the same way as with passwords, or passwordless-email. No CS-verified recovery needed.

> Why, for you as a service provider, are passkeys not just better (or at least equivalent to) passwords?

Why you missed the last line of my answer? How did you get an impression to go back to broken passwords?


All right, my framing was a little too tight. Sure I can see why an email/SMS passwordless loop is easier for you, but it’s a more annoying user experience than your OS/browser/password manager just filling in your credential directly.

They are not selling the information. They are selling a service for easy access to that information.

These are two different things.

Note: am not an AI fanatic.


Everyone here saying about execs and so on - don't seem to catch a few nuances in this chain.

1. Bill Gates is doing the "Internal Disruptor" CEO style

2. Everyone is reacting in a way Bill Gates expects them to react

3. The results of his disruptor style is that Windows is absolutely further unbearable and horrendous, as seen today own the line.

Make no mistake: "Internal Disruptor" CEOs kill their own products and people from the inside, rather than competing or building good products outside.


It's the inverse. We created a world for introverts only in the last ~50 years, where people can spend all their time in an office desk not actually talking to anyone. This was never the case in any of human evolution before.

It's only going back. Raw urban human connections will be the only thing left to exercise.


I treat any organizational theory that has a unidimensional view - like coordination is a good-to-bad slime mold – as incompetent, or at worst, corporate sabotage.

Any active product or business development - builds product/domain/operational depth. That depth feeds back into every decision.

Without taking into account that depth, complexity, competence of Managers and Employees in that depth, headcount invested into automation, etc, just focusing unidimensionally on some behavioral or organizational methodology, IMHO, makes it worse.

It gives CxOs some cute stories to blame someone or something against. If your coordination is slow, then there is a reason behind it. Find it.


Ops here. Don't use musl if you care about disk size or compatibility either. For reference:

docker.io/node:26-alpine - 61MB

docker.io/node:26-trixie-slim: 84MB

gcr.io/distroless/nodejs26-debian13: 55MB

Before this post, we have issues with different, slower DNS resolution in musl.

In 2026, there in no reason other than self-inflicted compatibility and performance pain to use musl in production services.

It has it's place, for binary cross-OS distribution, and generally having an alternate C STL. But avoid for SaaS.


Yep. The system in general is great for treatment, but fails for diagnosis. It takes them a long time to diagnose, sometimes years. But once they manage to do it, then they bring in all the heavy artillery and the health care machine works at it's best.

Sadly, it's often too late. Looks to be the case here, appears clearly a diagnosis delay. It does not take much for a skilled system to connect "airport worker" and the right lab readings together.

I can't imagine what these people would have gone through. They would have been given the "just a flu" treatment for some days, and then waited many more days for appointments. RIP.

PS: What you've said is pretty eye opening! This would amplify a lot of the diagnosis problems.


That's because lots of investment money go in treatments, not diagnosis. Diagnosed patients are captive consumers. They will pay to get better.

AI has the potential to help a lot with diagnosis, but considering that many relevant data don't even enter the system, I have doubts about how effective it could be. On the other hand, I would not trust a cloud AI (or cloud in general) to process my medical data. The temptation to abuse that access for marketing, profiling, insurance prices, etc. would be irresistible.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: