8 ms·
At this point why not just pass a one-time url link to your email address, and have it be a single click to login? Have it expire within 10 mins if not used, a
by dogcomplex 2y ago
At this point why not just pass a one-time url link to your email address, and have it be a single click to login? Have it expire within 10 mins if not used, and be one-time use disposable. Still, anyone who has the link initially should be able to login with your account - but it's only accessible from your email.
Obliterates all sense of security beyond the email account itself, but that's where we're at anyway. Do the same pattern with a message to your phone "click to authenticate login: www.someurl.com?p=134234535" and you've got 2FA without any dumb "enter this code".
- fragmede 2y agoThere are a number of sites that do exactly that.
- sunnybeetroot 2y agoI agree this is a great way but don’t forget not everyone is signed into email on their device.
- Saris 2y agoSome sites do that, like Netdata. But it's slow compared to my PW manager just autofilling a user/PW combo, since I have to wait for the email and go click the link.
- EasyMark 2y agoYep, I really hate when I have to go to email to get a verification code or click link to verify. I have a password keeper and 2fa for a reason. I hate the wait.
- dogcomplex 2y agoOh I dont mean do it instead of passwords (if you remember them), but just as an alternative to the Forget Password or Authenticate dialogs using security codes. Should just be a "LOGIN HERE" mashable button
- byteflip 2y agoI'm coding up a webapp with this exact login process - the issue I've found is on mobile phones - apps like gmail won't let you copy the link into a browser without a preview. The preview consumes the link. (next.js auth) It's a bit annoying, since I don't want to login into the gmail in-app browser, I want to login on my regular browser.
- aetherspawn 2y agoDon’t forget some people have antivirus scanners that will load up every link when the email is opened, so you can’t have the link expire after 1 visit. This is I think why unsubscribe links now have a single button saying “Unsubscribe” or similar when you press them. Likewise anything interesting should require a 2nd user action after loading the page.
- righthand 2y agoA work around could be: login link token is good for 24hours unused, or 5mins after the first use. That way you don’t leave the user in a loop or risk them not clicking the link within a short amount of time. The token still expires after a reasonable duration too.
- klabb3 2y agoYes easy mistake to make. But this goes back to HTTP basics: a GET request shouldn’t mutate state. Either don’t consume the link (ie allow reuse), have a user confirm action with POST, send a code instead. There are many alternatives. Personal favorite? Send a 6-digit code with ~1h expiry, exchange for a refresh token and keep the session for a long time. If you have really high value irreversible actions then you can just confirm with a new code. Also works if mail client is on a different device.
- dogcomplex 2y agoSend that code autofilled into the destination url form so it's a second POST click to login and sounds good.
- archerx 2y ago
- stavros 2y agoI do this for many of my web apps, it's confusing to users ("why do I already have an account here? I never signed up!"), expensive (email sending isn't free) and slow (sometimes the emails go to spam, sometimes they get greylisted and people can't log in for hours, sometimes it takes a minute to arrive and that's way too long to wait), etc. I don't know if I'd recommend it.
- echoangle 2y agoCan you elaborate on „email sending isn’t free“? What are you using to host the webapp? Can’t you just set up your own mail server and send whatever you want?
- imron 2y agoGenerally, no, unless you don’t care whether it’s delivered or not Too many people and companies abused this to the point that running your own mail server means much of the generic mail you send will end up in junk/spam folders.
- fooker 2y agoIt won’t even be delivered in most cases.
- echoangle 2y agoWhat would prevent delivery? I do some work for a small organization and we send out registration confirmations with a self-hosted webserver. I am not aware of any delivery problems there. Thats why I was surprised. Are we just lucky?
- m3047 2y agoYou are just lucky. You can contact me if you want to discuss further, I would strongly recommend you don't do it here.
- 2y ago
- j45 2y agoA pattern to make signups faster doesn't make them secure. Magic links can be more like convenience links, not secure, or security.
- hn_throwaway_99 2y agoI'd argue at this point that magic links are more secure: 1. Nearly every online service needs some sort of "forgot password" flow, and often times that flows boils down to what is essentially a magic link like TFA is about. 2. The vast majority of users these days use either personal email accounts from one of the big providers (Google, Yahoo, MS), or they use corporate accounts often through a hosted solution. 9 times out of 10 I'd bet the email provider has better security than whatever rinky dink website you may be creating an account on. Emailing magic links is essentially "poor man's SSO". It makes much more sense IMO to have super secure email accounts (e.g. ideally with passkeys) and then just use magic links for everything else.
- j45 2y agoLearning how to password effectively is something that comes up in B2B in many non trivial software. Magic link is effectively passwordless login, behind a facade outsourced to a third party provider. Passwords are much more actual consent, than clicking on a link in an email account that might be open on a screen or device... not always. SSO is technically easier than poor man's sso, it's just one click once logged in. Magic links make me switch a screen to make it easier for the developers of Magic Link to not implement SSO. Fingerprints are a username, not a username+password. It's super convenient, but well established not secure. Face-ID logins are more a username, should not be a username+password - selling it as secure is not ideal, but it is super convenient. SMS verifications too, are a little weak, since SMS' generally are like post cards. But they are very convenient. Until someone does something to get malware into your phone, or your phone number itself which seems to happen so often. Now, magic links are very convenient. And definitely can remove friction to you know, get a user onboarding to the point of adoption.
- dogcomplex 2y agoAgreed with OP, the security is basically nonexistent anyway due to Forgot Password flow making email the authority regardless. Sure, add a user/pass flow in addition for convenience and added security (i.e. delay the 3 minutes it takes to do a reset), but any real security would have to remove Forgot Password altogether or seriously delay turnaround time.
- layer8 2y agoBecause it’s still quicker or more convenient to use a password if you remember it or use a password manager.
- dugite-code 2y ago> Have it expire within 10 mins if not used Please never do this short amount of time. Email isn't reliable time-wise for delivery. You have systems like Postgrey (one of the basic spam protections for email servers) and deliberately pretends the email server is offline for emails from new servers until they server retries a set number of times. Not to mention if your email ends up in a corporate quarantine until you can request it released.
- suprjami 2y agoI use a web service which does this. It's mildly annoying having to switch apps/tabs just to login, but hey at least it's not another password to remember.
- archerx 2y agoRemembering passwords is easy this is just just convoluted and stupid.
- mewpmewp2 2y agoSince you wouldn't want to reuse passwords how is it to remember them?
- antimemetics 2y agoLet the machine do the work, sit back, and relax You have to remember 0 passwords and can still have a unique one for every account
- archerx 2y agoBase password plus company name or initials. One password mutated into infinite variations that are easy to remember. This has been working fine for me for at least 15 years.
- wyager 2y agoA lot of sites do this, annoyingly. I hate when my internet experience is degraded because the bottom pentile of users can't figure out how to do something.
- archerx 2y agoYes, why must the majority suffer because a few dumb dumbs can’t remember their passwords? We need to subsidizing stupidity or else we will get more stupidity.
- archerx 2y agoI hate this with a passion and many sites use it like anthropic and clipdrop, I stopped buying credits on Clipdrop because logging in was so annoying. My email is on my phone and I want to access the site on my laptop. This adds so much friction and turns a 5 second task with one to two clicks into a longer than a minute task with many clicks. I emailed anthropic about this and they did added a login with google option but just let us use an email and password please.
- adastra22 2y agoChrist, login with Google? I don’t have a Google account either. Why can’t they just have a username/password like the rest of the world?
- dogcomplex 2y agoWELL FUCK YOU TOO! - jk, I agree. Password option should be there still for saving sessions and avoiding this crap beyond the first registration (if you remember password), but I just meant this should be the baseline expectation of login flow. Oneclick google/facebook/etc too, despite those being an extra level of corporate data hell
- Too 2y agoAt that point you might as well go all in on single sign on. 95% of all users are going to be on gmail, outlook or apple anyway. Better to have a "sign in with google" button rather than "send a link to your (g)mail". They can track you either way.
- lxgr 2y agoPlease have both. We don't need more forced centralization when it comes to authentication.
- wruza 2y agoI love when sites do only that and then fail to deliver an email within 30 seconds. a message to your phone "click to authenticate login Should be both code and a link (enter 1234 or click <url>), because it’s not always the phone you’re loggin in on.
- dogcomplex 2y agoAgreed. Do password login option too if you remember it - all work - but point being just make it a giant "LOGIN HERE" button that just does the thing as mindlessly as possible.
- deleted 2y ago[deleted]
- sensanaty 2y agoI despise magic links. The rare few times I have to log back into Notion or Slack, I want to rip my hair out because of how annoying of a system it is. Please, for the love of god, just let me use my username/email and password. Have the magic link for the dummies that don't use a password manager if you have to, just let me do the username + password way.
- dogcomplex 2y agoI agree though the magic links should be the baseline default expectation of minimal registration/forgot-password effort
- adastra22 2y agoI don’t have access to my email on the computer in which I am trying to login to your web service.
- mplewis 2y agoWhy not?
- nucleardog 2y agoUsing someone else’s computer? Using a work computer that you don’t want your personal email downloaded on? Using a computer you don’t use often and don’t feel like setting your mail client up?
- adastra22 2y agoBeyond the valid reasons in the sibling comment (e.g. not accessing personal email on a work device), it is also a security risk. Access to your email is typically sufficient to gain access to everything else. I use an email for accounts that syncs with my phone only, and I lock it down tight.
- dogcomplex 2y agoHah this blew up. tbf I meant instead of any Forgot Password or Send Authentication Code or whatever mess - if you can remember your password, do that to save more time. Still, the loop to hit up email is so fundamental now the rest are secondary options - these Magic Links should just be the primary base-level expectation. It's annoying when services don't even get this right though and return you to the site with either: - a new form to enter the one-time code they just sent (just put it in the link) - a new form to enter a new password (who cares, make that optional to the actual sign in, to save time next login) - (worst offense): they don't even actually sign you in after those forms and you have to re-enter everything Login should be "do you have an email address? Okay great you're in". Because there is nothing beyond that from a security perspective these days.