5 ms·
I am starting a new site and want to avoid authentication. In our system, two users are linked together for the purpose of our service. We do that via unique U
by jbrun 16y ago
I am starting a new site and want to avoid authentication.
In our system, two users are linked together for the purpose of our service. We do that via unique URLs. Do you think it is safe to match up emails for authentication.
i.e. when user 1 wants to get his profile, he has to input his email and his partner's email. If he fails to do that then we do not pull up the profile. Does this make sense and do you think it is secure enough?
- Goosey 16y agoIt's pretty insecure. Beyond the obvious "I know both people and their emails and that they use this service" it would be trivial to do company email attacks (IE: all employees use (first-initial)(last-name)@(companyname).com so if I have a list of employees I can quickly access all combinations of those employees). No idea what your service is about and if that level of security matters.
- jfager 16y agoSecure enough for what? The attack is simple: pick a target whose email you know, and then start guessing emails of people you think they might have an account with. This could be as easy as browsing to a website and entering pairs of emails addresses listed on the "About Us" page, or ripping through a person's Facebook friends or Twitter followers. It might be fine for completely non-sensitive data, but for anything else, probably not.
- jbrun 16y agoYes, the data is not that sensitive, but it is valuable. It is all about brand preference and sizes for shoes and clothing. I just hate making users create accounts.