4 ms·
I recently used Vercel’s awesome magic link login. The feature was so awesome that I just needed to open the link in whatever browser. Unfortunately that also
by asiando 6y ago
I recently used Vercel’s awesome magic link login. The feature was so awesome that I just needed to open the link in whatever browser.
Unfortunately that also means that if I click the link by mistake the bad actor now has full access to my account. All just a misclick away.
- dewey 6y ago> Unfortunately that also means that if I click the link by mistake the bad actor now has full access to my account. All just a misclick away Doesn’t clicking the link set cookies in your browser that then authenticate your session? How would you clicking the link somewhere give access to an attacker?
- daveoc64 6y agoThe link in the email may or may not work that way - that would be down to how the authentication system has been designed. Some of them recognise that users aren't always signing in on the same device that their email account is set up on, so the link in the email just confirms that the login attempt is genuine. This is similar to how Google/Apple/Microsoft/Blizzard/Steam handle login requests with their respective authenticator apps. You attempt to log in on device X (which can be anything), then confirm that the login request is genuine on device Y (your personal device).