3 ms·
> Today I use auth0 configured as a passwordless solution, i.e. email code + login, or use Google OAuth, etc. This. Not necessarily auth0, but passwordless aut
by bmh_ca 9y ago
> Today I use auth0 configured as a passwordless solution, i.e. email code + login, or use Google OAuth, etc.
This. Not necessarily auth0, but passwordless auth.
Humans forget passwords routinely. It's at odds with realistic expectations of the human brain.
If email is compromised, so is the password reset mechanism.
Tacking on FIDO U2F and one can have reasonable expectations of identity.
No password DB exposure, no password guessing exposure, no remembering passwords so better experience and less support costs.
- homakov 9y agoIf not this protocol, I would be happy if any passwordless auth wins. Really about time to make a switch!
- dingaling 9y ago> If email is compromised, so is the password reset mechanism. If we didn't have online password resets then we wouldn't have to worry about the e-mail account being the weak-point. I would argue that no service that offers an online password reset mechanism deserves it. If I mess-up my bank login, I have to go to a branch to initiate the re-authentication process. Password in the post in secure-mail envelopes, things like that. If I screw-up my Amazon login - well, that should really be too bad, end of story. Just create a new account. There's too much risk in having an online reset mechanism that could enable someone else to use my cards for purchases.