avatar
Dr. K @drkamikaze.bsky.social

Email verification isn't super secure either. Now there's legions of sites that if one's email is hacked, it's simple to login. Email social hacking has been one of the top risks for decades now, I know so many this has happened to. It doesnt make my accounts more secure and it wastes my time.

aug 29, 2025, 11:01 pm • 0 0

Replies

avatar
Mike Sanderson @mikesand.com

Security analysis (i am a security researcher and worked professionally): if you could reset the password, then there's no change in the threat profile from a compromised email.

aug 30, 2025, 12:54 am • 1 0 • view
avatar
Dr. K @drkamikaze.bsky.social

yes, obviously, but that doesn't make forcing logins through emails any safer, that's my point. I don't want emails, I don't want texts, I use a password manager, just leave me the F alone and stop taking up all my time with this BS that doesn't make me safer!

aug 30, 2025, 7:06 pm • 0 0 • view
avatar
Mike Sanderson @mikesand.com

I hope we're not talking past each other, because this exchange is why you do NOT let security people control UX for your product, because security is always trade offs. That said, if email password reset was already possible then eliminating passwords objectively removes an attack path—at a UX cost

aug 30, 2025, 7:17 pm • 1 0 • view
avatar
Dr. K @drkamikaze.bsky.social

I'm not in security, so I believe you. We're talking about different issues. I don't want emails, I don't want texts, I don't want it to take 5 minutes for me to log into every fing website all day, that's my point. My life is being taken over by this shit and I'm fed up!

aug 30, 2025, 7:27 pm • 1 0 • view