Transcript

A tumblr post saying "i really like this thing where websites will have separate “log in” & “sign up” buttons and if you click “log in” it takes you to a sign-up screen anyway so you have to click “i already have an account” and then it will ask if you want to sign in with your facebook account or with instagram or linkedin or deviantart or whatever, and if you choose “username & password” it asks if you want to put in your username or use your thumbprint, and once you put your username & password it emails you a confirmation code, and once you put in the code it says “do you want to give us your phone number for future sign-ins? do you want to sign up for facial recognition? do you want to give us your bones? give us your fucking bones?”

  • JackbyDev@programming.dev
    link
    fedilink
    English
    arrow-up
    4
    ·
    4 days ago

    That’s all very interesting and insightful, but I don’t see how a site putting username and password entry on separate screens helps mitigate any of this, unless they’re doing something like showing ads on the page that asks for the username but not the one that asks for the password? I typically use ad blockers so I genuinely don’t know what’s standard. My gut feeling would but they don’t show ads on those pages at all. Apart from sites that have username and password boxes on the main page. But that’s still no reason to split the password from the username if both are on a dedicated page with no ads. I don’t see how it would prevent against fake password entry boxes either. Most of those sound like things the browser would ultimately need to mitigate against since any site could be compromised. Obviously sites have some role in it too.