53 ms·
Are Magic Links Outdated?
- astura 4y ago>Though no official record of the first use of this method seems to exist, research suggests that their concept dates to the early 2010s. Early 2010s? Craigslist has been doing this since the 90s.
- yababa_y 4y agoThey don’t seem that outdated to me, given the evidence presented. email provider security is a real problem but is usually considered the root of trust for persons…
- nnx 4y agoAlso a possible way for magic links to be secure even if email is compromised is for the requesting browser to create a secret client side so that only that browser can actually proceed with the magic link.
- joosters 4y agoIf the email is compromised, the hacker can just go to the front page in their own browser and generate a fresh login email, so there's no extra protection in client-side browser secrets.
- xxs 4y agoIt'd be ok, if there is (yet) another factor for doing this, e.g. SMS, time based tokens, and you'd need 2 of them to reset the 3rd. Cumbersome to put it mildly.
- DocTomoe 4y agoOne of the first things I learned when I got onto the internet was that "consider (RFC822) emails to be postcards analogs, readable by anyone who stumbles over them, they are not like mail which hides its content in an envelope." That was in 1994. Shirts reading "I read your email" were popular with the IT guys up to until about ten years ago (and they are still being offered). Email is an inherently insecure, non-trustworthy system. Considering it the "root of trust" sounds scary.
- yababa_y 4y agoand yet, it is! for many webapps, and not long ago almosy all. pop someone’s email and suddenly you have access to gazillions of account recovery flows. despite email’s flaws, it’s the defacto decentralized user namespace and authorization fallback. in the case of modern email, t only the sender, receiver, and a chain of usually-authenticated intermediates actually can see the contents of mail. it’s not completely plaintext anymore, i don’t think it’s as scary as you would think in 1994. and if modern email transports don’t count, then isn’t it true that _any_ messaging system could be considered as postcards in that whoever stumbles across the message contents can read it?
- DocTomoe 4y ago> if modern email transports don’t count, then isn’t it true that _any_ messaging system could be considered as postcards in that whoever stumbles across the message contents can read it? You are mistaking transport layer "security" with information security. It's a common, yet potentially grave mistake. Secure communication depends on encryption that is "good enough" so that unauthorised decryption takes too much resources or too much time to be practical, with the only encryption secrets being held by the sender and the receiver. We usually call that approach "End-to-end encryption", or E2EE. It is also something political entities try hard to ban, for obvious reasons, if you consider them mostly being suppressive-authoritarian surveillance state actors. (yes, I am aware of the '5 dollar hackwrench' xkcd comic [1]. If your state actor uses that tactic against you, you have a whole different problem). True E2EE solutions for email exist, but - mostly because virtually no one wanted the extra hassle - they never got adopted widely. In a perfect world, metadata would also be encrypted - or nonexistent at all (there are implementations for that, for example PGP-encrypted messages over bitstream over TOR (I know your 'bitstream address', but all messages get broadcast, e.g. via blockchain, to everyone, and you only pick out those that match your bitstream address. Because you have only your own private PGP key, you can't read the messages to other bitstream addresses, even though you have them). [1] https://xkcd.com/538/ https://xkcd.com/538/
- bradgessler 4y agoThat’s why I keep the harder-to-guess secret in the browser where the code request was initiated. If somebody read the code from your “postcard” and tried to enter it, they’d see an error and have to start over. Problem I have with most password reset schemes is they put the secret token in a URL, which is visible to all by the postcard analogy.
- amadeuspagel 4y agoI've been thinking about magic links using QR codes rather then email. EDIT: The idea here is that on a device where you're already logged in you generate a QR code, you photograph that code on another device, and then you confirm on the first device that it's really you who photographed the code on the other device.
- Mordisquitos 4y agoI don't understand. What would the QR encode? Surely not the magic link itself, as that would defeat the purpose.
- theginger 4y agoI think the idea is to stop mail providers automatically scannings the link, which would work until they start scanning the images for QR codes and scanning the links.
- withinboredom 4y agoI don't understand how this would work if you are getting emails on the device you are trying to sign in with. Most devices (other than Android?) don't let you scan a code from a photo.
- Mordisquitos 4y agoI don't know, GP comment said "rather than email" and not "rather than a link". Even so, the potential problem caused by email providers automatically calling links in received emails is trivially prevented by having a "Confirm login" button at the destination, as displayed in the visual example in the article. Also, using a QR would then rely on the user having yet another device at hand to log in, perform the often awkward scanning procedure instead of an ordinary couple of clicks/taps... to then finally log in on their phone and not on the original device they were aiming to (as well as making it less secure in a public surrounding against covert attackers in close proximity, but that's a bit of an edge case).
- 4y ago
- capableweb 4y agoArticle fails to mention that "Magic Links" are not only possible via email, but any out-of-band method, so you could use Whatsapp, Telegram or IRC even. Obviously, the user is assumed to have a secure setup regarding whatever method you send the link via. Which the "Email Security" section kind of hints to as well, that it's important users have a secure email setup. What they fail to mention, is that this is important not only if you use "Magic Links" but also if you have username+password login with "Reset my password" functionality, as otherwise intruders will be able to change your password anyways. In conclusion, the article seems to have been written with the goal of saying "Everyone is using Magic Links, how can we get them to use Zitadel (their product) instead?", rather than an honest look on how "Magic Links" can be made more secure.
- mffap 4y agoHow should an honest look at the topic include for your, that's lacking in the article? You mentioned the focus on email instead of other channels. Anything else? Thanks for the feedback.
- mooreds 4y ago> "honest look on how "Magic Links" can be made more secure" Challenge accepted. Here's my best practice list. (I should put this into a blog post!) * Prefer them for accounts that are infrequently used or low risk. * Test for conversion or goal uplift if possible with this. * Offer the user choices; some people will prefer username/password, some magic link, some social sign-on. * Ensure that users understand that whatever the destination is (email, whatsapp, slack, etc), the security of their app account is now tied to the destination's security. Understand that most folks care far more about their email or other destination than they do about access to your app. * Understand the UX tradeoffs (around mobile browser issues). Document them if possible * Make sure everything is over HTTPS. (Duh :) ). * Set timeouts for links appropriately and communicate that to your users. ("This link is good for X minutes." "This link expires at HH:MM.") * Warn users that access to the link is the same as access to the account. "Don't forward this email". I think that's everything I'd say. I would love to hear if I missed something.
- nibbleshifter 4y ago
- clement_b 4y agoI hate them. Force me to go to my mailbox while I have a good password manager and just want to use that instead. I get the idea, but this should be an alternative, not a default. Also sends loads of single use emails that will remain for ever in users mailboxes.
- joe_fishfish 4y agoIf it's magic link or multi-factor authentication, I know which one I prefer. Try explaining to an MFA-loving service that your phone is out of action while it's being repaired.
- deleted 4y ago[deleted]
- movedx 4y agoMicrosoft Authenticator - syncs your codes to the Cloud so you can pull them elsewhere (which your phone is out of action.)
- lostmsu 4y agoDoesn't that defeat the purpose to a degree?
- rakoo 4y agoThere needs to be a way to sync everywhere except the device you're connecting from
- gorjusborg 4y agoI use MS authenticator, and had the same thought. I came to grips with the idea that I really don't care all that much if a single factor has risks as long as the other factors have orthogonal lists.
- WorldMaker 4y agoMicrosoft thinks it is fine for most user's threat models because these use two stacked layers of encryption: your Microsoft account and either Apple's cloud backup encryptions or Google's. To move these codes between devices you have to login in both your Microsoft account and also your Apple or Google account in quick succession. I know on Apple devices it works in the same (iCloud) backup layer that disables other device keys so doing this on a new device will "break" access on the previous device (only one device at a time has access). (I'm not sure about Google's ecosystem.) You can't easily switch ecosystems with this. Microsoft seems to think it unlikely enough that both your Microsoft account and your device ecosystem account will be compromised at the same time that there is enough security in this depth.
- jarsbe 4y agoIt depends. I used magic links for a system where the user would log in every 6-12 months. It didn't make sense to force them to make a password.
- kevincox 4y agoWhy not? Most browsers are slowing pushing password managers on users and the experience is lovely. Register: 1. I click the password field. 2. I click "use autogenerated password" 3. Sign up. For login: 1. Click "login". The magic link experience is comparatively awful: 1. My email address never auto-fills so I need to click the field and select the completion suggestion. This is even worse if I am using a per-site email address. 2. Click login. 3. Go to my email. 4. Most often wait a few seconds. 5. Click the link. (add extra steps if I want to open in a private window or container tabs, or tons of pain for a different device) 6. Delete the email. 7. Find the new tab. 8. Maybe drag it to the right location in the tab bar or the right window. And that is assuming that my email providers likes your email and it doesn't get greylisted, put in spam or even outright rejected.
- DocTomoe 4y ago> Why not? Most browsers are slowing pushing password managers on users and the experience is lovely. Most browsers in 1996 had "save this password" functionality... it's not a new thing.
- kevincox 4y agoI think it has gotten more aggressive with popups to use a generated password appearing any time you focus a password field.
- mffap 4y agoIf you'd take a passwordless login with FIDO2 (now promoted "Passkeys" by Apple and Google) it would mainly require to use FaceID / Windows Hello / Fingerprint / PIN ... or whatever your devices deem necessary. Could be used on any and cross-device.
- robrobrobrob 4y agoMagicLinks are a mobile nightmare. Mobile email clients use their own browser and cookie jar which consume the session cookie you're trying to put into the user's main browser. This results in users 'never staying signed in' and a lot of frustration. Sending a one-time code via email fixes this, and is in practice about as easy to use as a link on desktop. In our app (Loomio) we default to magic/codes, but let users use passwords if they prefer.
- mffap 4y agoInteresting - thanks for sharing!
- kaichanvong 4y agoyeah on Discord this is almost magic.
- mooreds 4y agoLots of issues with magic links. And yet, and yet. For a certain class of accounts, I'm okay deferring to my email inbox. From a security perspective as a user, it's no different than deferring to a social provider like Google, but has the benefit in that it gives a user more control over the third party they choose to delegate control to. You allow username/password access and that's great too. I'm a fan of giving users options, but I don't know if anyone has done studies and found that a single login option actually is better for conversion. I'd be interested in seeing some numbers around that. I wouldn't recommend a magic link for high value accounts, but I have pretty easy access to my mailbox, from everywhere (in contrast to my password manager, which is cumbersome to use from different accounts). I can also forward the email with the link to any device where I have email. If it is a low-value account that I use infrequently, I'm a fan. The alternative is to just use 'forgot password' to get a link that resets my password. That is pretty much the same functionality. I guess the hard part there is that no one building software thinks their app is 'low-value'. :)
- TekMol 4y agoI wish there was a way to read all cookies of the current site and create a bookmarklet that sets them again. So I could log into GitHub and save the cookies in a bookmarklet. Then every time I want to use GitHub, I click the bookmarklet and it sets the cookies, so I am logged in. I dabbled with the idea a bit, but it seems not straight forward. Maybe due to some metadata that cookies carry. They are not just key:value pairs. For example here on HN, when I type "document.cookie" into the console, I get back an empty string.
- vgel 4y agoYou might be running into issues with session cookies and HttpOnly cookies: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#restrict_access_to_cookies https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#re...
- spicyjpeg 4y agoThat would not work for a number of reasons, the first one being the fact that virtually every service now uses HttpOnly cookies for session management (to make it harder for e.g. XSS injected code to steal sessions). In addition to that session cookies are usually rotated very frequently, with servers occasionally updating them even if you stay logged in; it goes without saying that if you log out and back in you will almost surely get a different session token each time.
- mojuba 4y agoAnother relatively new problem with magic links specifically on mobile is that your email client will likely open the link in an embedded browser which is typically isolated from the main browser app and doesn't share the cookies with it. There are some workarounds for this but they don't seem very secure, plus they add some complexity. E.g. once the backend validates the magic link click, it logs the user in also in the browser that initiated the email send. I think a sort of a phishing attack is possible here. Also the page that initiated it should periodically refresh itself to see if the session was validated somewhere else. I haven't been able to find any more secure or simpler solutions to this problem. Any thoughts?
- mffap 4y ago> Also the page that initiated it should periodically refresh itself to see if the session was validated somewhere else. I guess the link must be disabled / invalidated after first use and your auth server and client obviously must verify if a given link is still valid.
- mojuba 4y agoOf course the link should be invalidated, but that doesn't protect from a situation where an attacker initiates a login, then the user receives an email and clicks. The chances are slim but some people might get confused and click without much thinking - and voila, the attacker has a valid session.
- pritambaral 4y agoSimply opening a Magic Link doesn't have to authenticate the initiating login. The user can be asked to interact with the page, being shown the source of the link (time, browser, device, IP/Region, etc.), to authenticate the login. This adds a little bit of friction to legitimate cases, but then again having to open your email and find a link and click it is already plenty of friction that this additional step can be considered a negligible addition to that.
- ammmir 4y ago
- MrDunham 4y ago> Email Security: ...Should someone gain access to another user's inbox, they simultaneously receive the keys to logging into profiles that run on magic links. Therefore, a single cyber-attack on your email could lead to unwanted activity on many of your utilized virtual services This statement only partially covers the problem. I once had a cofounder leave my company on bad terms. He had access to the bank accounts, I had email admin. It took me 5 seconds to get full bank account access and lock him out with access to his email ("forgot password"). It's astounding how much of a skeleton key our inbox has become. This community doesn't need reminding, but our families do.
- pastage 4y agoI hope you do not use banks that use just email for authentication anymore. Horribly insecure.
- aaaaaaaaata 4y agoWhat bank due you use that's MFA key only, with no easy fallbacks?
- ricardo81 4y agoThe article doesn't seem to cover a potential issue- updating an email address associated with an account (2FA aside). If you've somehow lost access to email, a typical pattern is that you can login to your account, update the username and receive a validation email at the new address to confirm its validity.
- bamboozled 4y ago"Contact support to update your email"?
- bradgessler 4y agoI wrote a Rails plugin for magic links at https://github.com/rocketshipio/nopassword https://github.com/rocketshipio/nopassword that doesn’t suffer from many of the problems I’m seeing in the comments. The big thing is I only use a 6 digit numerical code that people have to copy and paste or type into the browser which they’re authenticating. I looked at stuffing a token into a URL, but it’s not a good idea because the email client may try opening the link to preview it or it may try opening the link in the wrong app/browser, such as an in-app browser. That may sound super insecure, but the 6 digit code is half the secret that’s needed to authenticate. The browser that the person is using to login has a much longer complex secret that must be included with the code. Additionally, this combination must be authenticated within a set number of attempts, 3 by default, within a certain timeframe, 5 minutes by default. My motivations for creating this, instead of using something like devise with passwords, is because I have seen soooooo many non-technical people get tripped up by passwords. I know there’s sign-in with Google, MS, etc. via OAuth, but I wanted to give people a way to login to web applications without being under the watchful eye of big tech. I’m currently using it in production for all of my Rails apps, like https://legiblenews.com/email_authentication/new https://legiblenews.com/email_authentication/new A better description of why and how it works at https://github.com/rocketshipio/nopassword https://github.com/rocketshipio/nopassword
- deleted 4y ago[deleted]
- aaaaaaaaaaab 4y agoSo if I have 700k usernames I can pwn one of them with 50% probability. Cool! With 3 attempts allowed I only need 230k usernames, even better! The "secret" stored in the browser doesn't protect you from this, since I'm not stealing someone's code; I'm logging in from my own browser. (Of course I'm doing this via a botnet, so you won't notice it by IP address)
- Isinlor 4y agoWith passwords you will get even higher probability if you just try 100 most popular passwords allowed by the service on hundreds of thousands of users. Try making password creation too difficult and now password reset will be the default authentication for a lot of users anyway.
- sborsje 4y agoThere's a near-infinite amount of not-so-small gotchas when implementing magic links: - If magic links are the only way to sign in, authentication success rate is now directly tied to your email deliverability rate. - Single-use tokens (immediately expiring after clicking) can be followed by spam filters, and thus immediately become invalid for the actual user trying to sign in. - MTAs using greylisting can cause unexpected delays in email delivery. - If a session audit trail is implemented, malware scanners following links might cause sessions from unexpected locations showing up. etc.
- matsemann 4y agoAlso, they only work if I have an e-mail client on the device I'm trying to log in from. Otherwise having to transfer this link becomes a burden. Additionally, even if I do have the e-mail on my device, clicking the link on mobile often opens it up inside some alternative web-view. Thus the session is tied to my e-mail client, not my actual browser.
- pritambaral 4y agoThis wouldn't be a problem if the Magic Link was used only to authenticate your original login session, and not to start a new session wherever it was opened. Like I mention here: https://news.ycombinator.com/item?id=32081608 https://news.ycombinator.com/item?id=32081608
- timwis 4y agoGreat points! The deliverability (and delay) issue is the one I’ve found most challenging. For the others, here are some mitigations I’ve come across: - instead of single use tokens, set them to expire within 60 mins - to prevent spam/malware checkers signing in when following the links, have the magic link take you to a page with a sign in button to ‘complete’ the sign in process. And, optionally, add some JS that clicks it for you on page load. This is the same approach used for unsubscribe links.
- mooreds 4y agoAnother issue that I don't see covered here is that some email clients (looking at you, Outlook) pre-fetch links to see if they are security risks. If you build a magic link system which handles plain old GETs, the one time code gets used up before the user can actually log in. We ran into this at FusionAuth and had to do implement some workarounds, documented here: https://github.com/FusionAuth/fusionauth-issues/issues/629#issuecomment-832778247 https://github.com/FusionAuth/fusionauth-issues/issues/629#i... Edit: https://news.ycombinator.com/item?id=32081192 https://news.ycombinator.com/item?id=32081192 mentions this and some other issues.
- ignoramous 4y agoI always say this to CISO-types: FusionAuth SimplePass is the real magic, not magic links; https://fusionauth.io/blog/2021/04/01/fusionauth-introduces-simplepass https://fusionauth.io/blog/2021/04/01/fusionauth-introduces-... elegant and yet zero attack vec
- ethotool 4y agoSomewhat related: https://news.ycombinator.com/item?id=31892299 https://news.ycombinator.com/item?id=31892299 This is very, very concerning and makes “magic links” a security threat to any platform that utilizes them.
- pjc50 4y ago"Opening an email and clicking on a link" is one of the most risky things you can do with your computer; it's a critical stage in many successful security breaches. Why would you train people to do it?
- bamboozled 4y agoAre you serious? I'm signing into a website, I get an email when I'm about to sign-in from said domain, I click the link in the email, I'm signed in. What is this training me to do exactly?
- roelschroeven 4y agoSome third party detects you're trying to sign into a website. The third party sends you an email, that email happens to arrive first. You click the link in the email. Now you're on a website that looks like the one you expected (if the third party has done its homework) but is completely in control by the third party. Apparently things like this do happen, for example when people are buying or selling things on the internet. They get redirected to a pay processing site that looks just like the one from their bank, but steals their money and/or identity instead.
- daveoc64 4y agoI'm not sure what actual security risk you're talking about here. I click the magic link, expecting it to sign me in, but instead it takes me to a fake copy of the website which then asks (again) for login details?
- OJFord 4y agoYes, a lot of people will fall for that.
- pritambaral 4y ago> but instead it takes me to a fake copy of the website ... This is fine, but ... > ... which then asks (again) for login details? This is where the trick lies. The third-party copy doesn't have to ask you for login details. As your parent states: They get redirected to a pay processing site that looks just like the one from their bank, but steals their money and/or identity instead. The fake site doesn't have to show you details of your account. It has to look just similar enough that enough people will think it's a legit payment site and submit their payment details. ---- There's also a simpler, alternative attack I mention in a sibling comment: https://news.ycombinator.com/item?id=32081724 https://news.ycombinator.com/item?id=32081724
- bamboozled 4y agoI think a lot of the complaints here are "nerd problems". For customers they seem like a super convenient thing, I was just implementing them in my app. Yes magic links have problems and it's probably making me lean more towards the "emailing a code" option now, some of those problems outlined aren't easy to ignore. The app I'm working on, users would login probably once or twice a year. I just can't imagine they want to deal with passwords, especially because my app is very niche, they'd use it once a year for one thing only. What I can imagine them having to do is constantly use the "forgot my password" feature anyway. For conversion easy logins are really important.Anyone have any better ideas than magic links, passwords or one time codes in email?
- wohfab 4y agoI mean, the magic link could be an addition to the "forgot password" screen, then? As in "reset password or login via magic link"?
- DocTomoe 4y agoI quit using services that have magic links as their only authorisation method - and so does my 65 year old, very non-nerdy mother (she complains about 'having to wait for a damn email' all the time) > Anyone have any better ideas than magic links, passwords or one time codes in email? Passwords. Password managers are not a new concept, they have been around for decades by now, have deep browser integration (either because they often are part of the browser, or in the case of Apple, the OS), and are easily understood by users.
- joshstrange 4y agoI'm in the same boat. People login 1 time a year (it's for an event) and using magic links means I don't have to deal with password management, forgot/reset password flows, and more. It also means signing up is as easy as entering your email (the web/app prompts you for the other required info on first login). Out of thousands of people who used the system I only had 1-2 people who had issues. One was using their work email (why do people do this?) and I think it was being filtered and the other was using Yahoo but for some reason the emails were slow to deliver, 2-3 minutes (far from the only Yahoo user, only one that had issues).
- deleted 4y ago[deleted]
- bob1029 4y agoI think magic links have some give/take depending on your product/platform/audience. One major use case that comes up more frequently is onboarding an untrusted device with a trusted one. WhatsApp seems to have mastered this class of problem using the QR code. Typing in codes and clicking emailed links is nice until you feel your phone's camera instantly log you in on your laptop by scanning its screen. The obvious downside is that this is a chicken-egg situation and you have to already have one chicken (or egg) to make it work.
- pottertheotter 4y agoOne of my healthcare providers uses this and I abhor it. With their website I can see appointments, billing, etc., but instead of simply going to the website and logging in with 1Password, I have to go to the website, enter my email and click log in, switch to my email and wait for the email, open the email and click the link which takes me back to my browser. It drives me nuts.
- timwis 4y agoIf you’re concerned about the security aspect of this, keep in mind that most web applications have this feature, but instead of calling it a magic link and for signing in, it’s called “forgot password.” It generates a short-lived code and emails the user a link that lets them access their account. There are, of course, challenges with this being the only (or default) way to sign in, but the security concerns with it (e.g. weak email password) probably aren’t new!
- ajsnigrutin 4y agoAnother account to lose, when google bans you, because your kid liked something on youtube on a family account.
- kazinator 4y agoThe magic link is basically using "forgot my password" e-mail recovery flow to just friggin' log in. If you've served the user a link which takes them to a session where they can change their password, that session must be authenticated, by definition; you would not allow an unauthenticated visitor to change an account password! And so, if that password change session is authenticated, then just treat that as fully fledged session. Don't force the user to go back to the login screen and use their new password. The next logical step after not forcing the user use their newly minted password is to just remind the user their forgotten password is still in effect, and that they can change it in their account profile settings. From there to "magic link" authentication is just some minor UI tweaking. I've always thought that asking the user to log in with a newly set password was an incredibly poor and unnecessary user experience, which just amounted to punishing the user for having forgotten their password and to train the user to believe that password recovery is inconvenient and should be avoided.
- postalrat 4y agoMany of my accounts I use the password reset feature then enter a long and secure password and never store the password. Next time I log in I reset my password again.
- kazinator 4y agoThus, if that password recovery continues to be a painful, multi-step process, rather than streamlined into an easy alternative login mechanism, those providers are basically not attuned to the way users are accessing the system.
- usrn 4y agoMagic links are half factor auth. They're probably good enough for apps that no one actually cares about though.
- postalrat 4y agoDoes that make a password + email password reset a quarter factor?
- joshstrange 4y agoA totally unbiased article for sure /s These guys sell a auth/login system, it's no surprise they are anti-magic-links. I understand the annoyances for the more tech-minded among us, myself included, but I've implemented this before and for your average user it's a pretty good system. With Universal Links/App Links you sidestep a number of the issue with email clients having their own in-app browser. Also this makes your signup/signin process the same flow (and only 1 step) which is easier for people who aren't as technically minded. I used this method for a food festival (you buy the festival's currency to spend on food/drinks, it's just a digital version of the paper/ticket/token-systems a lot of a festivals use) and we only had 1-2 people who had issues (email took a few minutes to get to them for some reason) out of thousands. It's all about knowing your customer base, in the future I might implement the ability to set a password but I'd be the number of people who use that option will be vanishingly small (again, based on the demographics of people using my platform).
- Spooky23 4y agoMagic links are great for low trust model applications where the user is required to use the app but is a limited stakeholder. Case in point: SportSignUp, which is a platform/app that allows you to manage your little league/basketball/soccer team, etc. The use cases for parents are basically figuring out where games/practices are, telling coaches that they will be/not be there, checking scores, and signing up to volunteer for various tasks. Life is complex. You have non-custodial parents, nannys, older siblings, etc helping out. The easiest path is to send the magic link to the family text group.
- planede 4y agoA lot of people brought up scanners that auto-click links. How do these scanners deal with verification email links or unsubscribe links in general? I mean unsubscribe links are commonly two-stage (you have to click a button on the target website), but now always. Never saw a similar two-stage verification link though.
- revskill 4y agoI think yes, because people hate magic ? Change it to Simple link might work.
- tomc1985 4y agoFuck magic links. What a horrible login flow. Am I the only person taht doesn't have my email open in another tab?
- jjoonathan 4y agoMy favorite is when a vacation or network change triggers what amounts to a cascade of security audits. Site A sends magic link to Email B, which in turn sends text to phone C but it never arrives, so everything times out. On the next go, Email B can be persuaded to send magic link to Email C which now wants a ubikey or password you haven't used in years. A simple login turns into an hour long slog -- with landmines! So far, I have been careful enough, but it's only a matter of time until this bites me.
- smt88 4y ago> Am I the only person taht doesn't have my email open in another tab? Magic links aren't targeted at the type of user you seem to be. Most users of most products are: 1) on mobile devices, and 2) use a native email client. They also don't have password managers, so magic links become a way to assume the security level of their personal email (which is what "forgot password" ends up doing anyway).
- tomc1985 4y agoIt doesn't matter. Crap like this makes the web worse. We cannot keep catering to people who refuse to learn better practices. If the industry got itself together enough to start teaching people good internet hygiene we'd all be much better off. But instead we strip away OK security for horrible security, and inconvenience nearly everyone in the process.
- smt88 4y agoMagic links are better security than most people's use of passwords. I can't count the number of people I know who reuse the same password on every site or just use terrible passwords. It took me years to get my dad and girlfriend on a password manager, and they're the only family I've succeeded with. It's the same with privacy. I could never get anyone to leave Gmail. You can't sell people on a major "inconvenience" by telling them about a hypothetical security breach. It's just not human nature. And even worse, the only good password manager that I've used is 1Password and it isn't free.
- amacneil 4y agoIt is strange to me that both this article and commenters in this thread complain about "email security" as being a limitation of magic links, given that the vast majority of password authentication websites allow an email-based password reset flow. Magic links aren't any more or less secure than allowing email-based password reset.
- Fnoord 4y agoExisted earliest in 2010? No way. Earlier. I remember in the 90s forgot your password link from e-mail signed you in, after which you could change the password.
- appleflaxen 4y agoThis is just an advert by a competitor.
- Kiro 4y agoI use Magic Links because I don't trust the security of my hobby app and don't want to deal with storing credentials. What I would like is a service like Firebase or OAuth but that I communicate with through my backend. So a user sends in username/password to my server and I relay that to a service which returns a token or something. I've had too many issues with the Firebase front-end JS that I no longer trust it to handle the whole flow. Anyone know a service like that? Basically just an API that is specialized in auth/security that I can outsource the data to without having to store it myself.
- zonotope 4y agoI haven't used it in a while, but it sounds like Auth0 [https://auth0.com/ https://auth0.com/] is what you're looking for.
- BoorishBears 4y agoAuth0 via Universal Login essentially fixes the crappy frontend JS problem, JS-free login page driven by an HTML template that you redirect to and get back a code There's also "dbconnections" endpoints where you can post raw sign-up data though if you're looking strictly for the backend piece
- parentheses 4y agothe problem with using this technique alone is it’s basically 1FA all over again. hacked email means everything is hacked. excluding the need to remember a password, how are magic links an improvement?
- dangus 4y agoThey’re yet another way for logging in to suck for people who use a password manager. Another example of this is consumer apps that insist that you should login with your phone number and make you click an extra button to change to the email login option.
- apeace 4y agoAnyone have advice for creating easy-to-use-yet-secure login solutions for users who are less tech-literate? My company is an ISP, and most of our customers are not very "good" at using technology. Any yet, they do sometimes want to log into our dashboard for one reason or another, and it tends to be a lot of trouble. We've found that: - Many people do not have an email. Some people don't have a phone number. Many people have only one or the other, but not both. - People typo their emails... a LOT. I initially had some very simple validation for email addresses, until I started getting droves of emails that were one character off. I'm at this very moment working on a feature to alert users if they type "gmail.co", "gmail.con" or "gnail.com", which are all very common (and two of which are completely valid domain names by the way!). - Some people get confused by "creating a new account" or dealing with multiple accounts in general. They'll say "my email login didn't work." Well, to me it's obvious that they have a different password for different accounts, but to them it's not. - Building on that, they are not great at password resets. The "send a password reset to email" thing is confusing to them, because from their perspective their email is the account. Am I resetting my email password?? They don't like it so they don't want to do it. - Since we are an ISP providing customers with WiFi, there is also confusion between the WiFi password and the dashboard password. I've had people successfully reset their dashboard password, expecting it to also set their WiFi password. - Literacy can also be less than ideal. I once reset a customer's WiFi password over the phone, and the new password contained an exclamation point. She didn't know what an exclamation point was. I got her to do SHIFT-1 eventually, but it took a while. (I found out later that nobody else sees an exclamation point as an "upside-down i", which is what I've always seen it as. The proper way to describe it to someone who doesn't know is "line with a dot underneath".) Now my password generator only uses A-Za-z0-9 (but not 0 or O). So, I have been learning the hard way that not every person in the world is an avid Hacker News reader who knows what accounts and password hashes are and how everything works. And yet, these people deserve to be empowered by technology just like the rest of us. The thing is, many of these folks are able to use software just fine, it's just that they have trouble getting logged in. It really is the logging in that trips everything up. So I've been thinking lately that I want to fix this for my company, but I'm unsure what to try. I had the thought of trying Webauthn, but that seems unusable for me as per this comment I wrote a few weeks ago[0]. If I could solve the problem in that comment, I think a lot of my customers would use "Login with TouchID", "Login with FaceID", etc. Anyway, my point is that no, I do not think magic links are outdated. We use a lot of magic links. Need to update your credit card? We'll text you a link. Want to reschedule your install? We'll text you a link. This is the best way we've found to actually get our software into the users' hands. [0] https://news.ycombinator.com/item?id=31850471 https://news.ycombinator.com/item?id=31850471
- capevace 4y agoMagic links can be very helpful when needing to authorise people from an external system without API access, and they recently saved our asses from having to process over 10.000 refunds manually. Let me explain: I work as a web dev for my local students union, and we recently had to develop a system to process refunds for basically every student there (9€ ticket related). However, our university wanted nothing to do with that process, so we couldn’t use existing student login infrastructure to verify refund claims and limit them to one per student. Luckily, each student gets a @stud.leuphana.de mail address. So all we had to do was send them a login link – if you weren’t a student or entered an invalid address you simply never received that, so you couldn’t apply. The system worked great and with few issues, thanks to magic links!
- ghostly_s 4y ago"Not device-dependent" is a false assumption. They are entirely dependent on you having convenient access to your email on the device. I have yet to to encounter one that was smart enough to authorize my session on the original device if I open the link on a different device (and there are probably good security arguments for not doing that). Even in the ideal scenario where I have a proper mail client, the alternative they present is: auto-filled password from my PW manager: 1 click magic link: click to initiate the login session (1); click to focus my email client (2); [wait for email client to launch if not already open]; click on the email (3); click the magic link (4) click to close the superfluous second browser tab (5); click BACK to my mail client (6); click to delete the now-useless email (7); click BACK AGAIN to my browser (8). Hate these things.