3 ms·
Not true! We have written this piece that talks about the security of magic links and how they can be used: https://www.ezid.io/resource/are-magic-links-secure
by dhruv_tek 4y ago
Not true! We have written this piece that talks about the security of magic links and how they can be used: https://www.ezid.io/resource/are-magic-links-secure https://www.ezid.io/resource/are-magic-links-secure
- nullfield 4y agoIt doesn't really matter if they're secure or not (but they're not). They're also infuriating, massively increase friction (especially for users of a web-based email system that they may not keep open) by forcing a user out of their workflow, as well as infantilizing users by deciding that for them that they just don't know any better and can't be trusted to use a secure password/turn on 2FA. If security were actually the concern, push users to turn on 2FA with a non-removable banner until they do it, and on that page prominently educate them on the best ways to smooth THAT out via the many 2FA tools that help manage logins, until we have a good 2FA standard or good, wide implementation of webauthn or similar. Perhaps we tolerate emailed password reset links currently until there is a better method. There's an additional advantage to them in that "if they work, you know they haven't been lifted/used, and your password still works/has been set". On the other hand, given that anyone can go ask for a login link to be sent as many times as they want, if you come home to a mailbox full of login link requests you haven't requested and which have already expired you really have no hope of knowing whether or not your account has been compromised/used for some nefarious purpose already. Even having immutable-to-the-end-user session info saved and displayed probably isn't enough to remedy this.
- prash_murali21 4y ago"you really have no hope of knowing whether or not your account has been compromised/used for some nefarious purpose already" this is an interesting point. Although the same would be true if your password to site in question itself got compromised, which is probably more likely. You wouldn't have any way of knowing if your account has been used for some nefarious purpose already too.
- orev 4y agoAfter reading that, nobody should be taking security advice from you and I would avoid using your product. Most of the piece is spent talking about UX (which is almost always in conflict with security), and ignored the extremely large problem that email is sent over the Internet without encryption, and then sits on some cloud server somewhere without encryption. Maybe that’s fine for managing a newsletter subscription, but it’s complicated inappropriate for anyone wanting real security.
- jaywalk 4y agoMost email these days is sent over encrypted connections and encrypted at rest.
- emptysongglass 4y agoI had to double take here because that just isn't true. I can't even remember when the last time was that I sent an email over the wire without encryption and if you're using one of the big free providers (most are) you can be absolutely certain those emails are encrypted at rest.
- jjav 4y agoSMTP connections tend to be opportunistically encrypted, but intercepting the connection via MITM is much easier than for e.g. a HTTPS connection. So while it's true that most SMTP connections are encrypted, that doesn't mean anything unless the endpoints are enforcing trust on each other which mostly they're not.
- orev 4y agoThe more we assume that everyone is using the big email providers, the more it becomes a reality. And everyone agrees that a centralized Internet controlled by only a few companies is one of the worst case scenarios. I have no certainty at all that any of those free providers use encryption at rest. How would they mine the messages for data to sell? And, cloud compute is expensive, and disk encryption takes more CPU cycles. Why would they spend that money? SMTP connections are more visible so it makes sense to use that from a marketing standpoint.
- jjav 4y agoLogin via URL ("magic link") is about as insecure as it gets. You can do worse, but have to try. Password reuse is bad because it allows compromising one site if another one is compromised. By sending someone a URL to login via email, now you've effectively forced password reuse of their email password as the site password (because obviously, if someone gets access to email they also get access to the emailed links).
- prash_murali21 4y agoI believe we have to view from the context of how most sites do auth, which is email + password with an 'email recovery' for the password. This is effectively the same thing with worse UX and an added attack vector of the password for the site being compromised. The point on password reuse I agree with, but flakiness here is that there do unfortunately exist dodgy sites without TSL and without password hashing and salting in place. This overall increases the probability of a breach and since re-use is common the supposedly secure sites become vulnerable too. At least with email, most major email providers have some level of securing the email (example 2FA involved when attempting to login from a different device). If the comparison is between email magic links and a site that offers email / password with no recovery at all or "secret questions" as the means of password recovery, which I haven't seen in years, that's a whole other debate all together.