Your article was well worth the read. Thank you for that. It's merely a HN trend where lazy people who can't read an article bad-mouth it as AI. You'll find the lazy AI comment in every article's top first or second comment now. Don't bother justifying yourself, keep it up and keep writing.
> what I'd REALLY F'IN LOVE to see go away is the passwordless/magic link auth flow
This seems really naive? That's the only flow that's at the basis if you get locked out. What else, do you put people on the phone to verify people by asking their name and date of birth? That's even worse!
I think they're referring to sites where that is the only way to sign in, which I have seen a few of. Basically you can never register a password or passkey, every sign in requires going to your email and waiting for the link to arrive.
I get the idea. If email links are secure enough to use for password resets, just do that every time. Then you eliminate a whole category of password attacks.
But it’s definitely annoying for a frequently used service.
Maybe this gets us closer to some idea of email being a more protected digital service, that has some legal guarantees?
Putting the potential negatives under the rug for a second…
I would be nice to have email that (1) you can’t get locked out of arbitrarily, (2) acts similarly to US mailbox (in its protections and universal service), (3) acts as an identity
Only if it's run by the state and free for every citizen. Forcing more bureaucracy on email providers will just make everything more centralized under Google and Microsoft.
It should be a mailbox with E2E encryption where the keys are stored on your ID card. Backups stay on secure servers that are legally protected from anyone including the police and only given out when you're getting a new ID at a government service center, encrypted with the cards public key so a hacker in the card issuing system can't steal it.
Every user gets a persistent address used as their identity, and any number of anonymous ones. Locking someone out would be both illegal and inconvenient for the government if all their official business is going through the mailbox.
Horrible idea. This will require every email vendor to certify with every country they provide service to that wants to do something like this, which will pretty much kill any small/indie email hosting providers.
I'd much rather have stricter legislation around password resets built into existing reg frameworks like PCI or HIPAA. If you store a form of payment or PII with a provider, then some form of human verification should be needed to perform a password reset.
I get more annoyed by the timeout it adds. Logging in 10 years ago? A thing of seconds.
Logging in today? Either magic links through mail (delivered to you within the next 30min thanks to graylisting or spam filters) or a login flow with requires 5 dialogs and 5 confirmation of "no, just log me in".
I think all Shopify sites also do it now? I'm migrating password managers and have been going over all of the old accounts I've had. Several sites that use Shopify for their stores now just don't accept any kind of a password.
I despise that too. One website (was it walmart?) gives me option to use that or a password, I select password and after entering it it tells me that it needs to verify my e-mail "for security" where I get link or code to log in.
At that point what's the point of password? Just an optional extra step?
For services that have your PII or payments details, yeah, that should be the only way to do a reset. Super inconvenient but much less so than dealing with stolen identity or credit cards.
It's the stupidity of Service Providers to adopt passkeys in the first place.
As a service provider myself, I've evaluated and said "Nah" to passkeys - because it's simply increased Customer Service contacts I have to invest in, whenever a user changes or loses devices, or any of the hundreds of ways Passkeys are not portable.
And guess what, the Tech companies pushing this have zero liability for user login support or security breaches. It's always me. There is no need for me to work hard and spend CS contacts, to wall off my users to the OS or Browser vendor.
I'll simply do passwordless Email or SMS 2FA / Magic Links and own my users without the overhead of Customer contacts, thank you.
I understand many passkey complaints but not this one. Why, for you as a service provider, are passkeys not just better (or at least equivalent to) passwords? You collect and verify an email address at signup and the account can be recovered in the same way as with passwords, or passwordless-email. No CS-verified recovery needed.
All right, my framing was a little too tight. Sure I can see why an email/SMS passwordless loop is easier for you, but it’s a more annoying user experience than your OS/browser/password manager just filling in your credential directly.
Everyone here saying about execs and so on - don't seem to catch a few nuances in this chain.
1. Bill Gates is doing the "Internal Disruptor" CEO style
2. Everyone is reacting in a way Bill Gates expects them to react
3. The results of his disruptor style is that Windows is absolutely further unbearable and horrendous, as seen today own the line.
Make no mistake: "Internal Disruptor" CEOs kill their own products and people from the inside, rather than competing or building good products outside.
It's the inverse. We created a world for introverts only in the last ~50 years, where people can spend all their time in an office desk not actually talking to anyone. This was never the case in any of human evolution before.
It's only going back. Raw urban human connections will be the only thing left to exercise.
I treat any organizational theory that has a unidimensional view - like coordination is a good-to-bad slime mold – as incompetent, or at worst, corporate sabotage.
Any active product or business development - builds product/domain/operational depth. That depth feeds back into every decision.
Without taking into account that depth, complexity, competence of Managers and Employees in that depth, headcount invested into automation, etc, just focusing unidimensionally on some behavioral or organizational methodology, IMHO, makes it worse.
It gives CxOs some cute stories to blame someone or something against. If your coordination is slow, then there is a reason behind it. Find it.
Yep. The system in general is great for treatment, but fails for diagnosis. It takes them a long time to diagnose, sometimes years. But once they manage to do it, then they bring in all the heavy artillery and the health care machine works at it's best.
Sadly, it's often too late. Looks to be the case here, appears clearly a diagnosis delay. It does not take much for a skilled system to connect "airport worker" and the right lab readings together.
I can't imagine what these people would have gone through. They would have been given the "just a flu" treatment for some days, and then waited many more days for appointments. RIP.
PS: What you've said is pretty eye opening! This would amplify a lot of the diagnosis problems.
That's because lots of investment money go in treatments, not diagnosis. Diagnosed patients are captive consumers. They will pay to get better.
AI has the potential to help a lot with diagnosis, but considering that many relevant data don't even enter the system, I have doubts about how effective it could be. On the other hand, I would not trust a cloud AI (or cloud in general) to process my medical data. The temptation to abuse that access for marketing, profiling, insurance prices, etc. would be irresistible.
reply