3 ms·
Think about it from the perspective of the site owner. Much safer to offer access this way, and easier, than having to manage and store and secure passwords. Mu
by hellofunk 9y ago
Think about it from the perspective of the site owner. Much safer to offer access this way, and easier, than having to manage and store and secure passwords. Much safer for users.
- nkkollaw 9y agoI'm not convinced. For the site owner, they can even more easily pick social login. As for safety, it's just as hard for a hacker to guess my email password then my website password, what is the difference? Not to mention that if my phone is around you might be able to see the URL from the lock screen, and if God forbid my phone (or even laptop, but it never happens) is unlocked my email client is accessible at all times without a password).
- hellofunk 9y agoBut if someone can access your email, they can already reset your password anyway. So email is the Golden Gate to your services in general, regardless of whether you use this approach. And the URLs that are sent out would not just be simple things that you could look at and remember and then go type them into some other computer. It comes down to ultimate safety for users and development time for vendors. I personally feel much safer knowing that some startup is not having to provide security on their own and store and manage my password and control all the things that my email provider does anyway. Because if that startup is hacked, there's much less likelihood of hackers walking away with credentials they can use later to access my account. Social sign on offers similar reliability and development benefits. The difference is that in my experience a lot of people are quite hesitant to use a social service like facebook to sign onto a site that otherwise contains important personal data. But I do typically work with customers who are older, so they're less likely to understand these kinds of practices. A very common misconception that I've heard many many times is people who think that because you login with a Gmail or a Facebook OAuth, that means you're giving those companies access to your account on our app. Seems silly, but a very common misconception.