Comment by baq
~0 people want to remember passwords. generating passwords for them without offering to securely store them in a password manager strikes me as misguided.
~0 people want to remember passwords. generating passwords for them without offering to securely store them in a password manager strikes me as misguided.
Yep, if that's possible for your service that works. If the service doesn't want your email and/or doesn't have access to your data, e.g. an E2EE service where account reset is impossible, then that's not an option.
The supposition for all this is that the service wants to use passwords for whatever reason. In that case, generate them for the user.
People should absolutely be using password managers where possible.
A website doesn't have control over whether you are using a password manager though. This is about stopping the human from generating a password themselves, which will be terrible.