4 ms·
I wouldn't call you crazy but I would call you naive. There are 3 factors, that I know of, for proving your identity: 1) Something you know (password) 2) Somet
by obpe 8y ago
I wouldn't call you crazy but I would call you naive.
There are 3 factors, that I know of, for proving your identity:
1) Something you know (password)
2) Something you have (phone or email)
3) Something you are (fingerprint)
Your proposal is to do away with 1 by relying upon 2. But the issue is the very nature of "having" something means it can be taken from you and, on the internet, quite possibly without your knowledge.
Further, your proposal essentially asks the user to completely trust every hop along the path an Email or SMS will take. You may be able to mitigate this by using an app but this is a significant step for many and not everyone has a smartphone.
So while your proposal may work for a tiny, inconsequential web site or service which contains nothing of importance (which begs the question why you have a login to begin with), I would never trust anything to a site that implements this.