

0·
1 month agoIf they wait a minute the passage of time ought to take care of it for them.


If they wait a minute the passage of time ought to take care of it for them.


I wouldn’t change my advice. Even if you go Argon2id, you still have a creds database to protect. If you let that go it’s just a matter of time before it’s useful.
You could go webauthn, but now we are back to passkey or windows hello or whatever. Which is what I told op, they invented passkey, and it’s Still third party reliance.
Source: I’ve been a software architect for 25 years.


You just invented passkey with oauth.


Sorry, yes it is. I’d really prefer it if software developers would take this more seriously. Managing user credentials is a high risk burden that you should avoid if possible.

lol “liberal”, I’m going to fucking die. You think china is liberal?🤣
Kid beer