2. What kinds of websites that require a sign-in are actually low-consequence? I can't think of any from the top of my head, but that's probably because I'm pretty reluctant to sign up to new sites.
2. What kinds of websites that require a sign-in are actually low-consequence? I can't think of any from the top of my head, but that's probably because I'm pretty reluctant to sign up to new sites.
It's usually not a function of the site, but a function of the site and the user. pg would probably care more about his HN account than user051783254. That said, some sites where I expect the majority of users (mostly the non-paying ones, but perhaps even the paying ones depending on the payment mechanism) would probably not care about their accounts being hijacked might include: HN, StackOverflow, CodeProject, AllTrails, Disqus, Last.fm, SlickDeals, etc.
Forum logins risk reputational damage, but otherwise are reasonably limited. Some people use specialist forums to ask one-off questions, for example.
What would worry me is if people hack the login for a low-consequence site and then figure out that those login credentials for this user are the same everywhere: at their bank, Amazon, etc. Personally, I use different passwords at every single website, but at low-consequence websites I sometimes use less secure ones. I don't see how this is a problem (for me).
I understand why low-consequence sites do not implement schemes to force users to use stronger passwords, though. Howls of outrage, lost users, and attempts to get around it, as charDiversity says: https://news.ycombinator.com/item?id=16975773
Or probably: sites that don't involve money.