4 ms·
So you don't want to sync passwords to your phone, but are happy syncing email, which would allow a far greater compromise (beyond just being able to magic link
by beecafe 5y ago
So you don't want to sync passwords to your phone, but are happy syncing email, which would allow a far greater compromise (beyond just being able to magic link or password reset you)?
- nickjj 5y agoI'm not sure how that falls inline with passwords vs magic links? Personally I have my email password remembered, I don't sync anything between my workstation and phone such as browser accounts or anything like that. All I know is, logging into a site using a magic link on a phone for me is much easier since all I have to do is check my email and click a link instead of typing a ~50 character randomly generated password that I made on my workstation when using the site originally. If someone already has access to my email then it's game over.
- Tagbert 5y agoIt’s great if that is an option for you, but for many of us, if a site requires email logins, it is a fail. Much of the time, by the time the authentication email arrives, the login timeout has expired.
- nickjj 5y agoIf a site makes it time out after 5-10 minutes that's on them. An hour should be ample time for it to be delivered while offering a decent amount of security around token availability, especially since it should be revoked as soon as it's been used once.