7 ms·
In the approach I described, you wouldn't be able to reset a password via email alone. You would receive a temporary password via email when you trigger the for
by j-berman 7y ago
In the approach I described, you wouldn't be able to reset a password via email alone. You would receive a temporary password via email when you trigger the forgot password mechanism. You'd then need to use the temporary password signing in from the browser that has the key still saved in local storage.
You can't sign in with just the temporary password. You need the key as well.
Using google or Apple like that would destroy the end-to-end encryption scheme
- ec109685 7y agoI see. Two factor: something you have: local storage key; something you know: your email account password. Lose your device and use only password manager in device and you’d still be out of luck. That said, do you think the threat risk of trusting Apple with the encryption key for end to end encrypting data with Sign in By Apple is much different than the approach you are implementing? In both cases, at least you wouldn’t have access to the user’s data and you have to trust Apple to some extent given they are in charge of securing local storage and device security.
- j-berman 7y agoIf you use a password manager to save your password and don't lose access to the password manager, you are safe. All you need is your password to sign in. I was only describing the hypothetical approach we're planning to implement for someone who forgets their password. And yes, if I'm understanding right, I think those threat risks are very different. One is trusting your device which you yourself have control over, the other is trusting a cloud-based service provided by Apple, which you do not have control over. Not everyone uses Apple products either :) Edit: But alas, it's a user's choice how they want to save their password. If Apple provides a static key over this service and users really want this option, it's definitely worth exploring further :)
- ec109685 7y agoGood point. I think what ultimately should be done is browsers should provide access to secure tokens that are stored in the user’s keychain (or Google equivalent). The Keychain is end to end encrypted and they have done the hard work in propagating data securely across devices. Then there are no passwords and user is in control over which devices have access to their data. Access to device equals access to data, which I think most people would be comfortable with (e.g. you don’t sign into your email account on your phone each day).
- j-berman 7y agoYes! This would be awesome