3 ms·
A one-time password system should also have a second token that was sent to the browser as a cookie over SSL. When the link is clicked the browser sends both to
by warrenpj 10y ago
A one-time password system should also have a second token that was sent to the browser as a cookie over SSL. When the link is clicked the browser sends both tokens (the cookie and the OTP) together. The password is only valid for one browser. Also the OTP should expire after a short time. [1] It has the same security properties as a federated identity service like OpenID (except that it is less vulnerable to phishing.)
Of course if you're talking about just a normal plain text static password, then it's obviously wrong to see it in an email.
[1] "Simple Authentication for the Web" (2007)
https://isrl.byu.edu/pubs/saw_TechReport%20%28revised%20March%202007%29.pdf https://isrl.byu.edu/pubs/saw_TechReport%20%28revised%20Marc...