4 ms·
But if someone can access your email, they can already reset your password anyway. So email is the Golden Gate to your services in general, regardless of whethe
by hellofunk 9y ago
But if someone can access your email, they can already reset your password anyway. So email is the Golden Gate to your services in general, regardless of whether you use this approach. And the URLs that are sent out would not just be simple things that you could look at and remember and then go type them into some other computer.
It comes down to ultimate safety for users and development time for vendors. I personally feel much safer knowing that some startup is not having to provide security on their own and store and manage my password and control all the things that my email provider does anyway. Because if that startup is hacked, there's much less likelihood of hackers walking away with credentials they can use later to access my account.
Social sign on offers similar reliability and development benefits. The difference is that in my experience a lot of people are quite hesitant to use a social service like facebook to sign onto a site that otherwise contains important personal data. But I do typically work with customers who are older, so they're less likely to understand these kinds of practices. A very common misconception that I've heard many many times is people who think that because you login with a Gmail or a Facebook OAuth, that means you're giving those companies access to your account on our app. Seems silly, but a very common misconception.