5 ms·
Sigh. We're working to normalize better UX around account security at https://clerk.dev https://clerk.dev It's a sordid affair, but we're making progress. We'v
by colinclerk 5y ago
Sigh. We're working to normalize better UX around account security at https://clerk.dev https://clerk.dev
It's a sordid affair, but we're making progress. We've reduced our average time to sign-in by about 20% since our launch 6 months ago. (There's nothing to say our starting point was very good, but we do think about this very consciously.)
If you're working to improve your sign-in flow, our biggest wins so far have been:
- OAuth buttons at the top, critically with Google included. OAuth is _way_ faster than passwords for most users, putting it at the top switched oauth usage from just below 50% to just over 50%. Those extra percent using oauth bring down the overall average speed.
- Eliminate OAuth "edge cases." Turns out, they're not edge cases at all. 15% of users will sign up with email/password then try OAuth next, or will sign up with OAuth then try email/password next. Make sure you have happy paths for these.
- Magic links instead of OTPs for passwordless auth. Overall, magic links are a few seconds faster than OTPs since there's no entry step. (That said, we're still investigating whether it's better to trigger OTPs on mobile devices because of the auto-fill capabilities)
- Integrate with password managers. Our sign-in flow is normally two screens, but if we detect a password manager we'll accept the password on the first screen. Password manager folks are already the fastest, but this makes them even faster.
This is just the first factor. Admittedly, our second factor is still lagging behind, but UX is getting better for 2FA with FaceID & TouchID. We're optimistic we can have a positive impact on the second factor, as well.
If you're interested in having a team obsess over this on your behalf, come check us out :)
- gjs278 5y agohow about username / password, no rules, and that’s it
- Wowfunhappy 5y agoHow about you allow me to turn off the second factor if I have a password manager, because I'm way more concerned about loosing my second factor and getting locked out of my account than someone somehow getting into my password manager.
- colinclerk 5y agoI personally use 1password for authenticator codes - highly recommend if you haven't seen it: https://support.1password.com/one-time-passwords/ https://support.1password.com/one-time-passwords/ Edit: Didn't answer the actual question - it's something we can look into. My instinct is that offering this wouldn't drastically change the security model, as long as we can be confident your password actually came from a secure password manager. Since some password managers (like 1password) are very strongly tied to devices, I think your ability to retrieve a password from it is a reasonable proxy for a possession factor. It's definitely something I'd want to read more literature on before building. That's just my instinct, and I'm half expecting someone on HN to share the attack I'm forgetting :)
- Wowfunhappy 5y agoBut doesn't this completely defeat the purpose of the codes, since they're no longer a second factor? I'd rather just not have the codes, as they're still a significant annoyance with next to zero benefit.
- colinclerk 5y agoThere are still some benefits. Your password can probably be bypassed with a "forgot password" flow while the TOTP code cannot. Aside from that, though, I think it's reasonable to argue that the security of password+code in 1password is equivalent to just password in 1password.
- aetherspawn 5y agoIf someone scrapes your clipboard or records your screen for example, this still adds a second layer of protection.
- Wowfunhappy 5y agoThey can't scrape the clipboard because of autofill, and they can't record the screen because passwords appear as ******.
- dperfect 5y ago> We've reduced our overall sign-in speed by about 20% So it's slower now, or did you mean to say you've reduced the time to sign-in?
- colinclerk 5y agoFixed :) Thank you
- rsync 5y ago"Magic links instead of OTPs for passwordless auth. Overall, magic links are a few seconds faster than OTPs since there's no entry step." I am willing to stipulate that magic links are better in this way. That is, provided they are of reasonable length. Say, 32 characters or less beyond the domain name itself ? You can't predict what device, or interface, or mail client one will receive these links on. You also can't predict how they will interface with the link (or resend or process it). The 300+ character hash links I sometimes see are really lazy and clueless.