back

by anderspitman·7y ago·view on hn ↗
No explicit backup, but I think you're also assuming Google-level lack of customer service. If someone contacted me telling me they lost control of their email, there's a lot of steps I could take to help them out short of telling them tough luck and them never being able to access their account again.
2 comments
True. And I don't want to be overly pedantic with the implementation details.

I like your proposal to remove passwords and prevent phising in general and I'm trying to give some honest feedback on what I think is wrong with this auth system.

The title of this post is "Tell me why this auth system is a bad idea", after all, not "Tell me the good parts of this auth system" ;)

I guess a question I would have for you is: name a few companies to which you would like to pitch this auth system. (e.g. your first few customers if you turned this into a startup or something)

This actually strikes me as a quite dangerous mindset! A lot of "hacked" accounts happen when someone tricks customer support. How, exactly, would you verify the customer's legitimacy?
By asking them their mother’s maiden name, of course!