4 ms·
I like to use passwordless email-auth, ie. send a magic link over email, they click it, and it cookies them, making them authenticated for some reasonable amoun
by Maro 2y ago
I like to use passwordless email-auth, ie. send a magic link over email, they click it, and it cookies them, making them authenticated for some reasonable amount of time (like 1-7 days). Obviously not strong enough for important things like banking, but for small apps used by a couple of people, it's fine.
Another layed of meta-security I like to use for private apps is to use a service like ipapi.co to do an IP->geo lookup, and then have a per-used list of allowed geo regions (usually at the city level), like:
{
"jane@gmail.com": ["New York"],
"john@hotmail.com": ["Clowntown", "Buffoonville"],
...
}
Depending on your user-base, this effectively shuts out 99%+ of the Internet. This geo check is trivial to circumvent if somebody really wants to, but it's good for keeping out 99% of random hackers.
- selbyk 2y agoI hate being forced to use passwordless logins. I avoid apps that do it unless I have to use it for some reason
- panarky 2y agoPasswordless logins where the session expires after a couple hours of inactivity are good for services that are prone to password sharing. For example, if you subscribe to Anthropic's claude.ai you can only log in with a magic link delivered by email, and it's a short-lived session. That makes it difficult to share one subscription with multiple people.
- fragmede 2y agojust setup an auto fwd email rule, or login to your friends email account. No one here would commit such a crime of opsec, but we're not most people.
- sixtram 2y agoI also like the magic link emails. I'm actually a developer on a SaaS product that makes heavy use of magic links. One downside - other than security - is that email delivery is not instant and these emails can end up in the spam folder. The wait can be frustrating. Magic links are usually good for users who are invited into a platform, for example to review a shared document or something.
- mejutoco 2y agoAnother disadvantage is that it assumes mail access on the same device where I am accessing the website. On a third-party machine it would be the difference between having one website compromised, vs your whole email identity.