4 ms·
A pro/con discussion would need a more detailed explanation of how exactly you plan to implement this. That said, some general advantages to having a permanent
by yetanotherjosh 16y ago
A pro/con discussion would need a more detailed explanation of how exactly you plan to implement this.
That said, some general advantages to having a permanent user-chosen password include:
- The user can login on any client even if they don't have access to their email on that device. In order to accomplish this without a user password, the user has to have their email device and the secondary device present at the same time, and you'd need to give the user a human readable OTP (one time password) they can enter into the secondary device manually.
- Convenience. Users doesn't have to visit their email to click an URL and can instead proceed directly to the logged in experience.
- Are you planning to give users a "log out" link, and then expect them to do the email hurdle each time? That additional email hurdle will encourage users to stay logged in when they might otherwise logout, which could make their accounts more vulnerable to theft. However, if you expect and want users to remain logged in for longer periods of time, it becomes more justifiable.
- For various reasons email delivery can be significantly delayed. It's not as much a problem now as it was in the past, but this lends email usage towards more asynchronous tasks where timing isn't terribly important.
- If you use a good password, it's more secure than email authentication. Remember that emails are basically the digital equivalent of post cards. But if you use bad passwords, like most users do, all bets are off, your accounts (email account included) are highly vulnerable to theft in any case.
- The URLs in emails will need to be designed so that they are only good for one use and time out after an hour. Otherwise gaining access to the email history or browser history becomes a means to steal login state. However, this also applies to the URL authentication that goes on typically in "forgot password?" workflows, so you probably have to do this work anyway.
- Users are sometimes reluctant to enter a valid email address for privacy and spam concerns. Often they will put in a garbage address just to get past that part of the sign up hurdle.
I'm sure there's more to say. That's what I can think of at the moment.