5 ms·
If users using weak/reused passwords is your problem, just don't let users choose a password (generate it for them), or don't use passwords at all (send link by
by devit 5y ago
If users using weak/reused passwords is your problem, just don't let users choose a password (generate it for them), or don't use passwords at all (send link by e-mail that adds a cookie), or use oauth login.
- folmar 5y agoLink-only login is the most underused security option, even more so for low-profile sites that need a minimal user account but do not really need full-on security.
- catlifeonmars 5y agoI’m curious. What is link-only login?
- toomuchtodo 5y agoA link is generated, emailed to the user, and clicking the link logs them in.
- nieve 5y agoI.e. what Facebook does if you don't log in for long enough. Two days ago I got a pair of messages to the same address with links to completely bypass login and verbiage about how they'd seen I was having trouble logging in followed an sms message with the same to a phone number they're not supposed to be using. It looks a lot like phishing, but it comes out of Facebook's servers and they've done it to me before.
- jrochkind1 5y ago> to a phone number they're not supposed to be using What do you mean?
- anthuswilliams 5y agoI'm not the poster you're replying to, but: Facebook collects asks for your phone number for security/account recovery reasons, but then turns around and uses it to market to you.
- deleted 5y ago[deleted]
- calvinmorrison 5y agoSo SSO but you have to trust the email provider instead of another random SaaS
- xboxnolifes 5y agoBasically. Most websites already make you login with an email and verify you have access to that email and use the email as a password recovery mechanism. May as well just use the email itself as the login. Of course if everyone did this, then all of your logins would have the same password (your email login).
- catlifeonmars 5y agoThis sounds more or less like OTP.
- folmar 5y agoIt does, but usually you also get a long-lived cookie and does not need any setup on the user side, so is nice for the non-technical users.
- folmar 5y ago... and some sites use it instead of passwords, i.e. there are no passwords at all, only email links.
- jimmySixDOF 5y agoSpotify use this