5 ms·
I must implement a members-only feature now in a website, where member access should be very infrequent. I'm considering implementing e-mail login (email OTP),
by helloguillecl 4y ago
I must implement a members-only feature now in a website, where member access should be very infrequent.
I'm considering implementing e-mail login (email OTP), but I have only seen it in Klarna. Therefore, I'm a bit worried of users not being familiar with the fact that they even if they didn't choose a password, they still have an account and/or profile.
Any thoughts?
- benmanns 4y agoI’ve seen more places use it. Sometimes called “magic sign in” or “magic links.” As a user, I don’t prefer it, but I’m also very comfortable using password manager. We implemented it at Doximity but I’m not sure how it changed sign in experience/metrics. It’s gated behind the “forgot password” link now rather than the default/only option. https://auth.doximity.com/magic_sign_in https://auth.doximity.com/magic_sign_in
- helloguillecl 4y agoWow thanks. I love the simple form you have there.
- matja 4y agoHow do you mitigate the privacy risk of mail providers reusing email addresses for accounts when their customers stop paying for services? (e.g., I heard that fastmail do this). For example, user@example.com signs-in to your site and stores data they expect to be private, they stop using the mail provider and the mail provider deletes the user's account which allows it to be re-used, then another unrelated user signs-in to the site and takes-over the account. I imagine the only viable way would be a whitelist of domains of mail providers that are known to not recycle email addresses (like Gmail), or to also check if the WHOIS data for a domain changed.
- akerl_ 4y agoPresumably the same way as any other provider: you don’t. Any service that allows resetting passwords by email has this risk, unless the service supports MFA and the user configures it.
- christiaanbrand 4y agoLike this: https://datatracker.ietf.org/doc/html/draft-wmills-rrvs-header-field-00 https://datatracker.ietf.org/doc/html/draft-wmills-rrvs-head...
- dathinab 4y agoIt could be worth to check the state of WebAuthn without HSK (e.g. using a TPM). If this is available friction-less for most (non advanced) users then this could be a nice choice. And the email OTP is only needed when they login from a new device (which you can detect and handle it roughly like a password reset workflow). Through I'm not sure what the state of WebAuthn for non HSK use-cases is.
- dathinab 4y agoI.e.: WebAuthn authenticatorAttachment: "platform" Using email OTP as "reset/new device" mechanism and fallback in case the platform doesn't support WebAuthn. Platform authentication means it uses TouchId/FaceId/etc. which people are already somewhat familiar with. And email OTP as password reset is something people are used to. (They are also often used to resetting passwords all the time on rarely used accounts.) The question is just how many of your users are on devices which support it. (And how hard it is to implement it with the tooling you use.)
- ComputerGuru 4y agoCraigslist on mobile defaults to logging in via a magic link sent to your email (you need to go out of your way to sign in normally). It seems to work fine for them and their particular user base. (I don’t like it: the thought of context switching (both mentally and physically) and especially on my stupid single-function-at-a-time iPhone does not appeal to me.)
- Macha 4y agoIt's incredibly annoying, especially when there's delays in emails or short lived codes. * I have to go do something else and sometimes forget to come back to what I was doing * It can be tedious if I'm on a device which isn't signed in to my email * It's a problem when I use container tabs to compartmentalise my email and now the link from my email is opening in the email container and not whichever container I wanted it to.
- plumeria 4y agoSpotify also has an e-mail login option
- Tijdreiziger 4y agoI think this is relatively common for 'secure e-mail' (e.g. doctor-patient e-mail). You receive an HTTPS link by e-mail, click it, and then receive and enter an OTP to read the e-mail content. The difference is that you don't have an account, just individual e-mails. Some sites also use e-mail OTP as a second factor (e.g. Steam and Humble Bundle).
- drusepth 4y agoSlack and their magic links are probably the most common exposure your users will have to this model. I can't speak on behalf of them, but I absolutely loathe sites/services that require logging in through email. It's fine if it's just one log-in option, but if a site makes it the only option, it's very likely I will not be using that site. From what I've heard from peers (both tech-savvy people using password managers and less-tech-savvy people confused by the seemingly-random tie-in to their email login), I've never heard anyone actually say they like the flow. In my experience, they very strongly dislike it. If you're doing it to "increase security", I recommend taking an approach closer to Steam: if someone logs in from a new or unrecognized device, send a code to their email and require them to confirm. It's still intrusive, but way less so since you have to deal with your email way less often.
- MBCook 4y agoI’ve seen it a handful of places. Overcast does that on the web. If it’s truly rare for someone to need to login it seems fine to me. If you keep session cookies around for a long time all the better. But if you need to re-login semi-regularly it’s a pain.
- tomc1985 4y agoPlease don't do this, email login is sooooo annoying
- marban 4y agoI use it on biztoc.com with a one-year expiration cookie — It sends you a direct magic link and a manual ~2hour pin that you can copy/paste. pin with a "—" separator for readability which gets ignored during validation.