3 ms·
This creates a dependency on the email. If your email gets compromised/locked, your account gets too. OTP passwords are better
by xdxfw 5y ago
This creates a dependency on the email. If your email gets compromised/locked, your account gets too. OTP passwords are better
- aaaaaaaaata 5y agoIs there any evidence that email accounts have done anything besides become stickier?
- withinboredom 5y agoSometimes, that’s exactly what you want though: you don’t care (and the user has bigger issues if their email is compromised) if the email is compromised. In the terms you might say “access is granted based on access to email that you register with” and if someone loses access to their email, you don’t need to do any id verification or “proof” to recover the account. You can just say “tough.”
- justsomehnguy 5y ago> OTP passwords are better For accounts which hold something of value (monetary and/or personal data) then sure. But every once in a while when I need to login to GitHub it blocks my logon and demand what I give it a code sent to my e-mail. In essence this doean't seems that different from the scheme in the article.
- cookiengineer 5y agoCredential stuffers will have a feast on this one.