3 ms·
True that the password reset and the "login" using this proposal travel the same path and present the same attack vector but there is some disadvantage to the f
by mgreg 11y ago
True that the password reset and the "login" using this proposal travel the same path and present the same attack vector but there is some disadvantage to the frequency in which the "login" system would travel down this less-than-secure path. The more times you use this the more likely that someone will just happen to be watching and waiting at the right time.
Let's not forget that most of the email system is still not encrypted (last time I checked anyway) even though the last mile between your mail server and your client may be.
- WorldMaker 11y agoFrequency is also essentially the same: you can request a new login token equally as often as you can request a new "Forgot Your Password" token in that they are both manually requested with only an email address. There are also already a growing number of users that use "Forgot Your Password"-only login (most accidentally; human memory is porous) day to day. Which is not to say that we shouldn't make email better and more secure, but that the security of our email infrastructure is a red herring of sorts in the larger security discussions of "passwordless" login, given that we are already equally insecure in every website that has a "Forgot Your Password" button that accepts anyone's email address.
- jessaustin 11y agoAn attacker who can "watch", can also click the "forgot my password" button whenever she happens to be watching.