You're wrong about LinkedIn, it's not the users, it's you
ufp.com
ufp.com
I can be diligent and yet one mistake can still expose the user's (hopefully salted and hashed) password. If there is a financial impetus for someone to find my mistake, they will spend the time looking.
As a side note, I'd love to hear how the hackers came to be in possession of 6.5MM LinkedIn passwords ... what mistake was made that allowed them to collect unsalted hashes in the first place?
Neither can the user. Users cannot remember a unique password for every site they visit. That's just not realistic.
The simple fact is that unique-password-per-site does not scale. Password managers don't work well, either, because they can't be integrated into the common mobile browsers, and they frankly just require too much user intervention. (Sure, I'll install this plugin on every machine I use, plus the gimpy custom browser for my phone and tablet, and I'll use the app to cut/paste into other apps that need auth...)
We really need to big players to get together and build a system that works, and for them to all implement it properly and push 3rd parties to use it. BrowserID seems promising, but I haven't heard of any other big players signing on to implement and support it.
I'm not familiar with how you write a web-app to use FB authentication - how much does using FB auth obviate the need for you to worry about user credentials?
Use FB by all means, but don't fail the auth if the user declines the extras.
I've always found it odd that SWEs can harbor this type of opinion. That is, "it's the user's fault for trusting me/us." when every other engineering discipline would consider such a stance insane. All other disciplines would place responsibility directly on the engineering team. Whether a plane falls out of sky, a car explodes when rear ended, a bridge collapses, a chemical causes cancer, or an oven electrocutes the user, in all cases we'd point the finger at the engineers (or company that performed said engineering) and demand an explanation. I see no difference here.
Full disclosure: This is coming from someone who was originally studying to be a ChemE before switching to comp-sci.
With all the leaks and concerns over privacy lately, I think we'll see some sort expansion of the laws covering PII sooner than later. So wether or not I agree with it, I think this will happen.
No, it's the user's fault for trusting any given site more than necessary. People outraged that LinkedIn leaked the same credentials that they use for PayPal, for instance. That is ABSOLUTELY a user issue. LinkedIn, and many before, screwed up. People aren't upset as much about the root screwup though (I mean just reset your password and move on), but that, yet again, it reveals that people rashly and irresponsibly reuse credentials en masse.
Your analogies -- if we accept that software should be built like a bridge (which is ridiculous) -- is misplaced. LinkedIn, like a bridge, should be built well to the limits of its purpose. If a bridge has a defect, however, it shouldn't cause my house to fall down as a consequence.
"It's not really about MD5, SHA1 or BCrypt, (...) It wouldn't matter if the passwords were all in plaintext if they never got out."
It is also about the hashes, because a good security infrastructure should anticipate the possibility of a leak and still protect the users.
For that, you need to use the right encryption so that users don't have to change their passwords in the next days, but have 5+ years for that.
And yes, I see that you are promoting dedicated authentication services (which would do it right), it just looks strange to me there.