OAuth wouldn't solve the problem though, it'd just move it somewhere else.
Use a different login for each site - use a password manager.
OAuth wouldn't solve the problem though, it'd just move it somewhere else.
Use a different login for each site - use a password manager.
As for your cautionary tale, I'm pretty familiar with the players here, axod. Why don't you tell us?
Probably for the average person though as you say, centralizing control is probably easiest until something like that happens to them.
Wouldn't an idea be to centralize this with your ISP? The ISP already knows who you are, seems like they would be a good authority on handling authentication to websites for you. (OK, doesn't work for when you're using some hotel wifi etc)
* Got locked out of their Yahoo mail account for a week
* Lost their GoDaddy account, got locked out of it, and had it redirected to a gay porn site
* Lost their bank account, had thousands in fraudulent charges racked up, and got locked out of the account
* Had all their Yahoo mailing lists scrubbed, and each mailing list member (including his kids soccer team, which he ran) spammed with gay porn stuff
* Had his tax dox and personal mail dumped in public.
It sounds like your Google experience sucked. But I can think of worse things that can happen than a beaurocratic SNAFU. Let's not just hope that people will get smart about their passwords.
I was picking up a friend (Todd V., long time lurker) for lunch, and he showed me the post since he uses the pwgen feature as well. I didn't know my password by heart, so he finally created an account and made the post.
Still not sure why it is getting voted down to -1 though, now that an explanation is under it.