in reply to Re^5: login with google account
in thread login with google account

... bcrypted passwords ... emailing password reset links ...

Those would certainly be big improvements. But something even more secure and convenient, such as OIDC, would be preferrable, imho.

Replies are listed 'Best First'.
Re^7: login with google account
by hippo (Archbishop) on Oct 12, 2024 at 22:17 UTC

    If you are after a data point I can tell you that I'm in favour of hashed passwords (bcrypt or otherwise) and I would not choose to login to PerlMonks via a Google account through openidc.

    FWIW, I miss BitCard.


    🦛

      Me too. I prefer to keep my logins separate, and wouldn't use my Google login for PM.

        Maybe we should also have 2FA.

Re^7: login with google account
by soonix (Chancellor) on Oct 14, 2024 at 06:25 UTC
    I guess that would then be "Login with an(y?) OpenID provider" instead of only "Login with Google"?
Re^7: login with google account
by ysth (Canon) on Oct 13, 2024 at 17:38 UTC
    We would use OIDC for the google account login, but it sounds like you are talking about something more than that. Can you say more?
    --
    A math joke: r = | |csc(θ)|+|sec(θ)| |-| |csc(θ)|-|sec(θ)| |

      No; in fact I can't even say that much. I don't know anything about it, really. I just know we need something better than what we have, and I think if we're going to change it we may as well come all the way to the present — no half measures. That's mho.