A: Not much.
It would seem extra security layers wouldn't provide much benefit.
A: Not much.
It would seem extra security layers wouldn't provide much benefit.
I sincerely hope you're either joking, or in no way responsible for the security of user accounts wherever you happen to be employed.
It's not as if HN is "feature rich" - the short comings are spread across the board, why should they implement a multilayer login security system but skimp on everything else? Have you ever done PCI compliance? Login is the tip of the iceberg! But that is exactly my point - HN doesnt need to do this stuff or become PCI compliant, because they dont store (very) sensitive information.
HN is a poor MVP at best. Its the community that makes HN amazing, not the product.
Protect their password as much as possible when interacting with your web app/website I would say yes.
I don't think about it as a responsibility rather just a nice or the right thing to do.
This attitude is absolutely not ok. You need to make sure the security of users accounts if a top priority, even if your app is 100% trivial in nature.