4 ms·
An interesting idea for a few reasons. Users don't have to remember passwords, which is a strong benefit, but the user's security is now dependent on the secur
by herghost 10y ago
An interesting idea for a few reasons.
Users don't have to remember passwords, which is a strong benefit, but the user's security is now dependent on the security of their mail provider, or their own security practices in relation to the use of that mail provider, and in all likeliness their smart device.
With the ubiquity of smart devices, this works from a UX point of view and could be really streamlined, but I wonder how much the meme at the top of the article is actually betraying - this is the service provider not wanting to be responsible for your security in relation to their service.
I'm not suggesting that this is unreasonable per se, but the ultimate evolution of this model looks like it could (potentially dangerously) increase the value of a smaller surface area (the smart device) and put a fairly huge onus on the end user understanding and being responsible for their security.
And whilst that seems ostensibly ok, we already know that the weakest link in security is the end user...so this could be putting all your eggs in one basket.
- askafriend 10y ago> but the user's security is now dependent on the security of their mail provider Let me put it this way. In many (but not all) cases I would much rather Google be responsible for my security rather than some random startup whose primary objective is to stay alive, not take security seriously.
- subkamran 10y agoIt's funny you say that because I feel the same way as a developer. However, users of my site wanted password-based logins even though I support multiple social logins (Google, FB, Microsoft, etc.). Granted, I use PBKDF2 salting and hashing and I take security seriously, but it's interesting how average people sometimes don't trust social providers or think I'm storing their credentials to that provider.
- adrianN 10y agoIsn't user security already dependent or their mail provider? Password reset mails are pretty common.