But it’s definitely annoying for a frequently used service.
But it’s definitely annoying for a frequently used service.
Putting the potential negatives under the rug for a second…
I would be nice to have email that (1) you can’t get locked out of arbitrarily, (2) acts similarly to US mailbox (in its protections and universal service), (3) acts as an identity
Is this a bad idea?
I'd much rather have stricter legislation around password resets built into existing reg frameworks like PCI or HIPAA. If you store a form of payment or PII with a provider, then some form of human verification should be needed to perform a password reset.
It should be a mailbox with E2E encryption where the keys are stored on your ID card. Backups stay on secure servers that are legally protected from anyone including the police and only given out when you're getting a new ID at a government service center, encrypted with the cards public key so a hacker in the card issuing system can't steal it.
Every user gets a persistent address used as their identity, and any number of anonymous ones. Locking someone out would be both illegal and inconvenient for the government if all their official business is going through the mailbox.
I only need a new login link when I switch to a new browser or device, so it's not really annoying at all.
Though next time I'll probably try oidc if I can find a common provider that isn't a hassle