18 ms·
Ask HN: Why aren't one-time sign in links more popular for authentication?
Tying a OTP to an email appears to be more secure than the cluster that is remembering and managing passwords.
- marcus_holmes 6y agoHonestly, having a password manager makes this so much easier. I still like the OTP process, but it is more hassle than using the password manager.
- raxxorrax 6y agoAnother name of OTP in E-Mails are capability URLs and they are used quite frequently. https://www.w3.org/TR/capability-urls/ https://www.w3.org/TR/capability-urls/ There are some problems though and the authentication could be called weak. Problems is that URLs aren't regarded as secret and the irrational tendency to log everything doesn't help, as these OTP will be visible after a while. So these OTP have to be invalidated at some point as they tend to become revealed. If expiration is necessary, you still need some form of auth to regain access.
- minitech 6y agoCompared to saved passwords in terms of usability: it adds extra steps, potentially several, which is annoying. Compared to passwords in terms of security: you have to consider that the client visiting the link might not be the client with the session being authenticated, at which point there might be confusion over multiple authentication requests of mixed legitimacy around the same time. I don’t know how this is typically solved. I think better than either for security and usability is passwordless WebAuthn with a local factor (e.g. Touch ID for Apple devices, or even a master password for a simple improvement over existing password-unlockable saved passwords), if implementing something outside the status quo. (edit: starbugs’s point about latency is also very important.)
- max1truc 6y agoThe problem there is that if your email password is found (cracked, leaked, etc.) your account is pwned. However, due to the "recover password" options, your other accounts are pwned too. Finally, if you ever loose your email password, you won't be able to access any of your accounts anymore...
- hestansy 6y agoA lot of OTPs are implemented in insecure ways - e.g. using the "recover password" functionalities you can often figure out patterns the websites are using to create these OTPs. Some websites / apps do not implement account lockout and OTP expiration mechanisms and have 3-digit codes, which allows for brute-force attacks. Others with these mechanisms can lead to DDoS. Also, some web apps log these OTPs directly in the URLs. In general, I agree with minitech in that WebAuthn with a physical factor would be better, both in terms of usability and security.
- asutekku 6y agoIt's inconvenient. That's the primary reason why it won't gain mass adoption since any obstacle to your service will lower the registration / engagement metrics. With password managers built into all modern browsers, casual users (which, lets be honest here, are by far the most of the web users) do not have to worry about typing passwords. Security be damned. If it is not invisible to the user, they will reject it.
- _carl_jung 6y agoPassword management is better, not worse, for security.
- elwell 6y agoWhat is your argument for that? That people will choose better passwords (unique and long) since they don't need to remember them? The Achille's heel of password managers is if someone accesses your computer (physically or remotely) they can probably access all your accounts. <-- and I've seen this happen (not to me)
- andrewzah 6y agoIt's much more difficult to compromise someone's computer than it is to obtain/get one of their passwords thru phishing/guessing and then try the combination on a bunch of sites. It's -vastly- better for casual users to have secure, single-use passwords instead of what most casual people do: have 1-2 insecure passwords with variations. Thus allowing any phisher to get access to everything anyways. Just because something isn't perfect doesn't mean it is not an improvement.
- kevincox 6y agoIf they can access you computer they can probably also access your email and get the sign-in links.
- _carl_jung 6y agoThis is not possible if your password manager itself requires a password. Unless you mean "password managers don't work because someone might know the master password" which is true, but realistically the alternative is just using the same weak password all over the web, which is way worse.
- jedberg 6y agoThere is a service that I use that uses these. About 90% of the time what happens is I go there to use it, get the thing that says "check your email!", and then get distracted on my way to my email. By the time I finally get to my email, the link is expired and I just give up. Consequently, I almost never use that service.
- asiando 6y agoI recently used Vercel’s awesome magic link login. The feature was so awesome that I just needed to open the link in whatever browser. Unfortunately that also means that if I click the link by mistake the bad actor now has full access to my account. All just a misclick away.
- dewey 6y ago> Unfortunately that also means that if I click the link by mistake the bad actor now has full access to my account. All just a misclick away Doesn’t clicking the link set cookies in your browser that then authenticate your session? How would you clicking the link somewhere give access to an attacker?
- daveoc64 6y agoThe link in the email may or may not work that way - that would be down to how the authentication system has been designed. Some of them recognise that users aren't always signing in on the same device that their email account is set up on, so the link in the email just confirms that the login attempt is genuine. This is similar to how Google/Apple/Microsoft/Blizzard/Steam handle login requests with their respective authenticator apps. You attempt to log in on device X (which can be anything), then confirm that the login request is genuine on device Y (your personal device).
- GTP 6y agoFrom a cryptographic perspective, when dealing with authentication the different methods fall in one of the different categories: 1) Something you know (e.g. a password) 2) Something you have (e.g. a token) 3) Something you are (usually biometric authrentication, like your fingerprint, a retina scan...) Real OTPs fall in the second category, because you have some device/application that is able to generate the same OTP code as the server handling authentication without communicating with the server. Now there are some popular solutions that are still being called OTPs that instead of something you have is something that is sent to you, like SMS OTP. This isn't just quibbling, because sending something each time authentication is needed, opens up the possibility for some attacks that wouldn't be possible with proper OTPs, e.g. SIM swapping. So to answer you question: - Just having to click on a link sent via email has the problems outlined in other comments - having to both enter a password and having a link sent to your email address is safer than just enter a password, but - having a true OTP, like the TOTP standard, is what provides the best security (in the category of OTPs, I'm not talking about protocols like FIDO2 and similar, because I don't know them). EDIT: formatting
- squiggleblaz 6y agoEvery system that relies on passwords also provides a password reset facility. The facility typically sends a token to your email address and allows you to set your password that way. Doesn't this mean that a system which relies on an token sent to you is no worse that a system with a password? With a password, you can guess that GTP used the same password on Hacker News and BigBank, and if that fails, you can try and have their token redirected to you. Without a password, you have to rely on getting that token. So if your argument is that email and SMS are insecure channels, I mean yeah okay; but it doesn't make a system more secure if you can get in with a password _or_ an email/SMS vs the only option is an email/SMS. I hate passwords; my password manager (the one built into Firefox) will generate passwords on my desktop, but most of the time I need to generate a password it's on my phone (where, oddly, they have not included the capacity to generate a password). So my password is crap, perhaps not stored, and I forget it. I rely entirely on the password reset facility. But most of the time if you tell me "please just sign up, think of a unique username and a secure password" I'm just not going to bother.
- starbugs 6y agoWe have tried this for a while and the following reasons made us kill it: 1. Email delivery latency: depending on the service you use, the time it takes to deliver emails to the user can vary. Worst case I encountered was up to 20 minutes delay when there were issues with Mailgun. 2. Usability: you have to leave your current app and switch to your mail client. You may be on a device where you don't have a mail client installed at all, so you have to provide a password login option as well. 3. The sign in dialog gets more complicated and it's hard to explain to users how it works as it is not all that common. This also had effects on sign up/sign in dialog design which we found to have a negative impact on conversion rates.
- innocenat 6y agoI resonate deeply with this comment. As an extension to your second point, sometimes I want to login to a service on a shared/public computer out of necessity. I'd really not want to login into my email on said computer too.
- Nemo157 6y agoA good one-time-sign-in-link implementation will send a link to authenticate a session elsewhere, so you can click the link on your phone to complete login on the computer.
- szszrk 6y agoThat's kind off what Microsoft does in Microsoft Authenticator. It doesn't ask for password, it sends notification to you phone app and asks you to tap "65". The app then shows 3 numbers, one is 65. You log in on the other device after tapping. No passwords entered at all. They did a nice job on that one.
- sam_lowry_ 6y agoWhat if we just allowed sending one-time links not only via mail, but via Telegram, Whatsapp, Messenger, Signal and a bunch of other options?
- 6y ago
- MattGaiser 6y agoIt’s irritating and would clog my inbox.
- numbsafari 6y agoTake all the time and energy you will put into this and instead invest in making sure your sign-up and authentication flows work with popular password managers.
- factsaresacred 6y agoFriction I guess. Having to open a new tab...wait seconds(!) for the email to appear...click a link which opens another tab. Nah, just let a password manager handle it.
- OJFord 6y agoAs a user, I hate it, it's a PITA, why be different, 'everyone' 'understands' passwords, we expect them.
- Veen 6y ago> why be different Because, although everyone understands passwords, they have security and customer experience issues: - Users choose easily guessed passwords and get hacked. - They use the same passwords on multiple services and get hacked. - They forget passwords, requiring an email reset, so they need to access their email anyway. - The service doesn't need to store and manage passwords. Every authentication method involves tradeoffs, and the service has to decide which set of tradeoffs they prefer. Personally, I prefer passwordless logins, but I understand why they're annoying for some.
- compsciphd 6y agoIn Israel a lot of services are tied to an SMS based OTP (including government services), so one doesn't even leave the app. the app reads the token out of the SMS and fills itself in (of course if that fails, you can still enter it manually).
- sgt 6y agoOn the Mac, Safari has that built in, if you get an SMS (delivered to the same Messages app as iMessage), the browser knows about it and you just select "Use 1234 from Messages".
- szundi 6y agoSo many nice insight. Thanks. What about a use case when it is inconvenient to create another password for a new user base at a company and this way you have users without calling support all the time.
- Brajeshwar 6y agoFedex have a login with an OTP via email. The OTP expires in 15min, while the email came 30+ minutes later. I exhausted the 5 tries because I keep hitting the button. I had to wait another days for an International delivery! Imagine that.
- jitl 6y agoIf a customer loses access to their email (because they left the job or graduated, say), in the email/password world they can log in and update the email. In the OTP world the user is screwed.
- robertlagrant 6y agoI'd rather that auth apps with a push notification prompt became more popular instead.
- indymike 6y agoEmail and sms are prone to delays that make the experience bad for users.
- jwr 6y agoOh, this is so terrible. I hate this approach with a passion. E-mail is NOT INSTANTANEOUS. It was never meant to be. It happens to arrive quickly for most people most of the time, but you should never, ever, base a service on that. Many systems have greylisting in place: a new sender gets a 4xx reply, and is allowed through only on subsequent retries after a pre-set time period. This is often as much as 30-60 minutes. It's a good approach to reduce spam, it turns out a lot of spamming software does not bother to retry, or doesn't want to incur the cost. So, if you try this OTP-over-Email approach, you end up with frustrated customers, who 1) have to wait up to 60 minutes, 2) their OTP doesn't work, because you expired it after 5 minutes. It's terrible. Don't do it.
- progval 6y agoAs a user, I have the same issue but in the opposite direction. My greylisting config requires only 1 minute wait, but many providers only retry after 5-10 minutes. Usually I can request a new login (or email verification) link and it will go through immediately. It does not work with Sendgrid-based services though, as Sendgrid rotates the IP used by the service for every mail.
- wruza 6y agoWhy can all instant messengers do this “instant” part and email cannot? I’m aware of mta chains, decentralization, etc, but heck.
- Someone 6y agoBecause, as jwr says, it was never meant to be. The mental model is that of regular mail that gets collected at post offices, then split by major destination, sent on, and finally ends up in a mailbox. Mail servers do not even have to be on the internet (https://en.wikipedia.org/wiki/Non-Internet_email_address https://en.wikipedia.org/wiki/Non-Internet_email_address), or on a network at all. It was fairly normal to have a time sharing system dial in to a mail server every day for a few minutes to exchange mail messages (https://en.wikipedia.org/wiki/UUCP#Mail_routing https://en.wikipedia.org/wiki/UUCP#Mail_routing)) Also, of course, it is harder to accomplish in a decentralized system that isn’t controlled by a single party.
- ffpip 6y agoNotion [1] used to do this. It is pretty bad for signing in. You have to be logged into your email, wait for a six digit OTP and then use that for logging in. [1] - https://notion.so https://notion.so
- mjl- 6y agoi'm using this approach for a project (for a customer) where they don't want their users sharing their login details (username/password) with others. so it's a way to keep some control over who is accessing the system. the assumption is that people won't share credentials for their mailbox with others. email is still mostly sent as plain text over the internet, that's certainly a downside. email delays haven't been a problem in practice for us. we also send users notification emails with links going directly to the right page, automatically logging the user in. i would like that from other services as well, as i'm browsing with ephemeral browser containers. having a clean browser environment triggers some website (eg github) to verify my login with a unique code sent by email. that indicates email delays aren't a showstopper in practice at big scale either.
- tatersolid 6y ago> email is still mostly sent as plain text over the internet, that's certainly a downside. Opportunistic TLS for SMTP seems to have been dominant on the US portion of the internet for nearly a decade. Especially as email is concentrated in a few huge providers who have been using STARTTLS for many years. I say this based on the systems and logs I have monitored in that same timeframe. In fact, many email systems (mostly corporate MS Exchange) appear to be configured to reject or spam-bucket email connections that don’t support STARTTLS with a public CA certificate. (This observation may be biased by covering the financial services industry more than others.)
- aikinai 6y agoIf you make a new account on Yahoo Japan these days (not really related to original Yahoo and extremely successful in Japan), they don’t even let you set a password; you get an email link every time.
- mihir6692 6y agoAuthenticators are much better options then email links if service wants to go for password-less login. P.S. authenticators have their own problems too just like E-mail. :D
- radu_floricica 6y agoI'm assuming you intend those links to be single-use only and expire automatically, in which case what I'm writing below doesn't apply. Nevertheless, the problem is big enough to be worth repeating and re-repeating: Any link that ends up in a browser address bar should be treated as public. And no, it doesn't matter if you use HTTPS. Ways to leak it are many, but the gist is that it's treated as "meta-data" and, rightly or wrongly, subject to much lower expectations of privacy. A recent scandal was that several common browser extensions collect this meta-data and sell it to marketing companies. Which marketing companies offer searchable subscriptions (for hefty prices, true, this isn't a $9.99 service), where somebody could for example search for "yourcompany.com", or even worse, "yourcompany.com/authernticate?token=". Yeah, meta-data.
- squiggleblaz 6y agoHow do you advise we handle email address confirmation and password resets?
- aaronhayes 6y agoAutomatically expire the links
- squiggleblaz 6y agoYeah but you can do that with login token URLs as well. The person I replied to said "you can never do that", not "you can do that only if you exercise suitable caution". I am asking for an alternative that fits with the "you can never do that" perspective, not a way to backpedal.
- squiggleblaz 6y agoApparently I completely ignored the first comment in the original post. Apologies.
- hnick 6y agoI was working on an ecommerce site once and we got emails when customers left reviews/feedback. I forwarded them to customers because it was a convenient way to show their comments then follow up. Then I noticed that some of the text was wrapped in a tokenised link to the platform managing our reviews, bypassing the login screen. Support said they could not revoke these tokens. We had to close the entire account and migrate everything.
- Sirikon 6y agoEmail sometimes takes too much to be received by the user, but the approach could be handy in other contexts. For example, some time ago made a Slack bot with a web dashboard. The authentication method was based on introducing your Slack username and the bot would send you an OTP. The latency problem didn’t exist here.
- sneak 6y agoEmail is not a secure delivery mechanism. Everyone has an HSM in their pocket these days. The fact that we are having these discussions at all is ridiculous.
- eeZah7Ux 6y ago> HSM in their pocket If you refer to the typical smartphone, it's an HSM without the Security, and also it's not truly Hardware.
- searchableguy 6y agoSubstack and scaleway use email link as their primary authentication system. Wonder what the impact of that has on both of them?
- bronson 6y agoSome people use mail clients that either preview or spam-check links. Every OTP you send them shows up as "already used." Then they blame you and not their mail client. Related, I've consulted for a company that downloads and caches every link in every email passing through their corporate server.
- CodesInChaos 6y agoSince HTTP GET requests are specified as not having any significant side-effects, I'd blame your app as well.
- lol768 6y agoMonzo do this as their primary authentication mechanism. No complaints with it.
- topherhunt87 6y agoTried this recently on a small SaaS app; users complained nonstop about the inconvenience of having to switch to their email client. One key thing I overlooked is that the service is often used in academic presentation situations, where you're trying to log into the service on a 10-year-old lectern computer where you aren't logged into your email account. I reverted to the generic UN/PW approach and the complaints disappeared; passwords aren't perfect, but at least they're compatible with sticky notes. Plus, users prefer the familiar. I won't try the one-time-link approach again unless the app's specific use case makes passwords extra painful.
- huhtenberg 6y agoOne-time links are invalidated by various automated scanners that "check" emails upon arrival, including visiting all contained links. This is very common in enterprise setups.
- PedroBatista 6y agoBecause when I want to login I WANT to login - It's amazing how much it's spend on shaving milliseconds yet having such an indirection doesn't ring a bell as a problem. Also, having such a critical part of your system depend on email delivery and access? Looking at most frontend development practices I understand the blindside/YOLO attitude these days but it's still a bad idea anytime of the day.
- shireboy 6y agoI know a guy who as a matter of course sets his passwords to long random strings. When he wants to log into something, he then uses the sites’ “forgot password” as his “OTP” to assign a new one, log in with it. He does not store the random string, so his password is random, he doesn’t know it. Sounds like a lot of trouble, but my point is “forgot password” can kinda be otp for those paranoid enough.
- weeboid 6y agoOTP, with extra steps :D
- motohagiography 6y agoGiven a scheme is only ever as secure as its recovery process, he's not wrong.
- newscracker 6y agoThis is fine until a platform or service decides to lock his account or permanently disable it because of frequent password reset attempts. If he’s lucky, he may be able to use a phone number connected to the account to get in. If not, then that’s the end of it. Seeing the kind of login patterns that many sites track for security reasons and how bad their judgments can be, I personally wouldn’t take such a risk.
- bvcvbuiy 6y agoI do that for some services I rarely use. That works actually fairly well.
- sirodoht 6y agoI used to add this functionality to all my projects, as it’s much better not to have a password. Now I don’t like it at all. It’s very inconvenient to have to switch to your email when you could just auto-fill with your password manager.
- nickjj 6y agoI think it depends on what the sits is for and how cookies are handled. If your login mechanism sets a cookie after they verify the link then they can continue to be logged in for 3 months or however long you want. This is similar to what you would do with a password. Also the site type and your audience makes a big difference. I wouldn't do it on a site where folks aren't technical. But for example what about an ecommerce site where customers need to register an account + put in credit card details to place an order and then they get access to digital goods? In the above case the lack of password is a benefit because it simplifies the payment form. Now they only need to put in an email address + card details. And for getting access to what they purchased a slight delay isn't the end of the world. You could even give them access to it immediately in some type of unverified way (limited features until they verify). Also it's a slight deterrent for account sharing.
- habosa 6y agoBesides what many others have said, I'll add that many low-end Android phones are likely to kill your app when the user leaves it to go check their email. Which is fine, you can handle it, but many apps add a flow like this and aren't ready to be killed in the middle of their sign-in flow because this never happens on an emulator or a high-end test device.
- code-is-code 6y agoThis. Same happens with the sms verifcation in microsoft teams. On older devices switching to the sms app will restart the teams authentication process. So you have no chance in every typing the correct 2 factor sms key.
- ytch 6y agoHow about scan QR code on login screen by authenticated APP on phone. Many companies in China use this way. does there have any possible exploit/disadvantage of this method?
- gruez 6y agoDisadvantages I can think of: * requires app: This is the main killer. I'm not going to install some random SaaS vendor's app on my phone just so I can log in * requires internet access on phone: sucks if your phone doesn't data, cell reception is spotty, or wifi isn't set up * less phishing resistance: one time sign in links are impossible to phish, and passwords have mitigations that protect against phishing (eg. password managers that only auto-fill on the correct domain) and users are generally aware to "check the address bar before entering password". scanning a QR code has neither of these.
- kevincox 6y ago1. I don't want to install you app. 2. I don't want to find and pick up my phone. 3. How do you log in to the app? This has a bootstrapping problem.
- deleted 6y ago[deleted]
- tarun_anand 6y agoWow... amazing response to this questions. We have been researching this as well for a product. I am surprised to see that so many people have issues with email delivery. Though email delivery can be delayed and in theory there are no guarantees. Have you considered using SMS or a 2FA App like Duo? They should be near instantaneous. The idea of sending this over telegram or signal is a good approach though the costs of Whatsapp messaging would be prohibitive. Even SMS will not work at scale. So really boils down to 2 things (1) Speed - can you service live with delays or provide an alternate? (2) Cost - this cannot be tied to the per message cost like transactional or promotional email/SMS. A different pricing model help.
- ch0I9daAiO 6y agoLosing your email or domain would also be a problem.
- z77dj3kl 6y agoWe implemented a passwordless, OTP-to-email login system, and doing user research, people just complain it's too complicated. They don't like logging in to their Gmail and (as others have mentioned) waiting a few moments. It's especially bad on something like mobile. People like to use passwords, apparently. I see passwords as reducing security (we have a low-security product so people can reset with an email, so security-wise, the upper bound is your email security), hence we used it. But people prefer the "remember the secret" shortcut!
- sethammons 6y agoWhy not use some federated log in like Okta? Not as many issues as email on the delivery side.
- runako 6y agoPasswords are free, Okta is not. Also creates a ton of friction for users, most of whom will not have any federated login installed.
- bravoetch 6y agoIt's unpopular because it doesn't solve user issues. It solves vendor or engineering issues.
- yowlingcat 6y agoReally fascinating subject that I've been thinking about a lot lately. At $FewCosAgo, I inherited a codebase which used passwordless login via SMS. SMS has a ton of intrinsic security flaws because of SS7 so there are obviously risks with this method. But with that said, it worked very well for the exact same reasons email doesn't here: SMS delivers nearly synchronously, and it was rare to end up in a situation where the login text didn't send to a user. After going through the flow a couple of times myself, I was shocked at how much more I felt inclined to test my own software just because logging in was so much lower friction. Regrettably, the issues with passwordless email/SMS login mean that for now, if there's no OAuth provider you can/want to use, the ol' password is probably still the best way to go.
- runako 6y agoBecause it's awful. A normal flow for me is credentials stored in browser/password manager. Login is more or less seamless, and typically takes under a second. OTP login is multiple steps, involves me doing a copy/paste (or remembering the code), and requires a mandatory delay while I wait on the email. If I wanted to login incognito, or in a different browser, I may have to copy/paste the URL etc. A better question is why anyone uses them at all given how bad they are. I've stopped using at least one site because it exclusively uses OTP links.
- weeboid 6y agoTo truly advocate a position here, first the LCD must be reasoned for, which is, "my grandmother", or "cool and always drunk uncle", or "xyz frat bro/sorority sis"
- beh9540 6y agoWe tried this on a b2b SaaS product I worked on where we had a lot of "third party" users (volunteers for a customer) who were only going to use the application once a year at most. One of the biggest hurdles we had was explaining it to enterprise customers - when they were doing their due diligence, it didn't "check the box" and we had to change it pretty early on in order to accommodate this.
- Willamin 6y agoI wonder why SSL Client Certificate Authentication hasn't become popularized for the web. 1. Browser visits a site that needs authentication. 2. Browser checks if there's already an existing client cert. 3. If not, browser generates one. 4. Browser uses it in the SSL handshake, resulting in the user being signed in without passwords, cookies, email links, etc.
- jon-wood 6y agoBecause the UI for managing client certificates is terrible, with no real support for distributing a cert to multiple endpoints unless you're in an enterprise environment with device management, or issuing smart cards and readers. I do think there's legs in client certs for enterprise authentication, but for consumer products it's a non-starter.
- jchook 6y agoI wonder if this is something that cloud password managers like 1Password could tackle.
- gfodor 6y agoIsn't the problem with this that it means your account is tied to your browser install? Eg, you'd need to copy the cert to another machine to sign in, would need to ensure it's backed up, etc.
- randomdata 6y agoPassword management already is to basically that extent and the tools to copy that information around, backup, etc. also have come into existence to support usage beyond a single browser install.
- gfodor 6y agoThat's half true, password management piggybacks on top of a system which doesn't have these characteristics, so it means no special work needs to be done on the development side to support them, and it's activation function is only determined on one side of each edge (the user side.) For this cert system to work, you have a bit of a chicken-and-egg problem since it requires both sides of the user-service graph to have done work pre-emptively to support it.
- j45 6y agoA consideration I see is the tradeoff between security and convenience. Where email appears as a push notification on an imap idle configured email account, email can be far more unreliable, even with the best transactional email services.
- emidln 6y agoScryfall.com (a Magic the Gathering search engine and deck building site) does this and the experience is very nice. I'd have to check, but the session Scryfall uses feels pretty long. I rarely, if ever have to authenticate again on the same browser/machine. This would likely be more annoying if I had to do it every day.
- pchm 6y agoDescribed my (negative) experience with magic links in my SaaS in another thread recently: https://news.ycombinator.com/item?id=25465021 https://news.ycombinator.com/item?id=25465021
- Abimelex 6y agoThere is basically not much difference than sending "reset your password" email like all the time you want to log in. Keeping this in mind it seems ridiculous using SSO via email.
- sgoto 6y agohttps://twitter.com/samuelgoto/status/1346145032663756805 https://twitter.com/samuelgoto/status/1346145032663756805
- lacker 6y agoThe California DMV does this as part of their “upload documents ahead of time” system, and it is a terrible experience, because they often tell you to wait for an email and then no email arrives. What happened - is there a problem with my spam filter? Is there a backed-up queue in the DMV software? Do they simply consider it acceptable if the email takes an hour to be delivered? If you use this method then you really need to care about your email deliverability and that is harder than just maintaining a regular login process.
- stemlord 6y agoIt means I have to go sign into my email account just to retrieve the OTP to sign into this other account.
- shaicoleman 6y agoThe biggest downside is email isn't reliable - it's slow, it gets filtered, and sometimes it doesn't get delivered at all. For example, I've been locked out of my Patreon account for the last couple of weeks since Gmail decided to return 550 errors (address doesn't exist) [1] and they require an email to log in when the IP address changes. Most likely my email address has been added to the suppression/bounce list of Mailgun. * https://news.ycombinator.com/item?id=25435916 https://news.ycombinator.com/item?id=25435916
- nojvek 6y agoWow. All the hate about email OTP. It’s an amazing feature that I use all the time. I believe slack popularized it. Security and comfort are sometimes at opposing ends. 1) it’s unreasonable to expect people to remember so many passwords. I forget passwords all the time. Password manager isn’t that great since it doesn’t work cross device. 2) even with OTP, email is slow. Also email can distract and adds friction 3) federated auth such as google/GitHub auth is great. I usually get in in a single click. I’d say if you want to prioritize you prolly get the best bang for buck in following order 1) federated auth - no need to store passwords, no forgot password flows. It assumes your audience is okay with google/GitHub/Twitter etc auth and has an account in one of the services. 2) email/pwd. More complications but benefit is it depends on no 3rd party. 3) one time link in email. The benefit is user doesn’t need to remember password. It does depend on email which adds some friction. Note: you can have all 3 options and let user choose for maximum conversation. The tradeoff is more work on your side. Life is all about tradeoffs. No one right or wrong solution.
- slovette 6y agoI personally think nearly everyone here is wrong. Working in IT with a direct day-to-day relationship with end users, passwords are the bane of all existence. You say email delivery or sms is slow, but how often is it slow for users? Data on this? I personally have never seen a significant delay for an OTP code to either my inbox or my email (Google & Verizon). I have seen users that have an old email configured that is no longer active, but, oh, 80% of the time their cell number is a backup, so resolution is easy enough for them. You say it’s insecure? Really? So the more than 30% of your users that have their password written either on paper on their desk (most commonly a sticky note or in a small notebook just hanging out on the paper pile) or in an unencrypted note taking app is somehow more secure? You say it’s inconvenient? What? It can’t be more inconvenient than having to go through a password reset process once a week (which believe it or not, a TON of end users do). Is any one actually measuring this or is this as an complete echo chamber of nerds that are good with password managers? Because I can tell you with certainty there’s a whole demographic, generation of humans out there where single token logins (backed up by multiple OTP at certain time or event trigger intervals) is BY FAR AND AWAY A BETTER WAY! You want an example of who I think has this perfected: Affirm.com
- bvcvbuiy 6y ago> It can’t be more inconvenient than having to go through a password reset process once a week (which believe it or not, a TON of end users do). That is what I do with many services I use. I ask a reset password link every time I use them. I then just copy paste a random passphrase as new password and forget about it.
- derangedHorse 6y agoContext switching really is a huge hassle which is why I absolutely abhor email logins. We as user have become privileged with high speed interactions on the web and any hit to it will definitely have an effect on user retention. Also keep in mind that most internet services are bottlenecked by network latency. When asking a user to login with email it adds in the time the user takes to physically navigate through the pages of the email client and the 'n' network requests needed to open an email and follow a link. See https://www2.deloitte.com/content/dam/Deloitte/ie/Documents/Consulting/Milliseconds_Make_Millions_report.pdf https://www2.deloitte.com/content/dam/Deloitte/ie/Documents/... for more information on how cutting hairs on latency can dramatically affect an application's adoption rate
- mohshaheen 6y agofirst time i have seen it was in slack app , i liked it and i am using it with SMS /twillio whats app in mobile apps with mobile deeeplinking from appgain.io