-
Notifications
You must be signed in to change notification settings - Fork 35
Open
Description
The "Legacy Password Generator" just makes SecureLogin even more difficult to understand. Is it really useful?
My understanding is that user email serves no purpose in your system. Why not removing it?
Asking for user email has the following drawbacks:
- More complex UI
- End users will think you'll use their email for some dark purpose
- Cryptographic expert will say that using a piece of public data to generate a secret is a weak spot
I know you use the email as a profile name. See below.
Understanding what "profile" is about is difficult. It is just a character string to identify the active password, isn't it? I suggest you:
- Forget about the term "profile"
- Replace it by the notion of "active password" and "password label"
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels