3 ms·
Or maybe password managers need to catch up with this newly forming flow
by seanthemon 2y ago
Or maybe password managers need to catch up with this newly forming flow
- abdullahkhalids 2y agoKeepassxc (and its browser extension) can do this easily. You just have to one time define that the website only takes a username field. After that it will autofill the correct email in the field.
- wpm 2y agoPerhaps, a password manager managed email address used solely for these stupid links and codes. Why email then? Why not some other, better protocol? Why not just use a TOTP at that point?
- al_borland 2y ago> Why not just use a TOTP at that point? Friction. When the username is an email address, 100% of people logging in have an email address. Telling someone they need to setup TOTP, especially if they have never done so before, is going to be a bridge too far for something they may only use once or twice. One site I remember using this email code login was a small online store. If I was prompted to setup TOTP to buy something, I would have probably not bought anything. If my mom was prompted for that, she’d end up calling me, and I’d have to try to walk her through the whole thing… then I’d keep getting calls the next 5 times she’s had to login. If the site gives directions on what to do, they will probably only be written targeting a single authenticator app. For people who don’t yet know that the apps are generic (in most cases), this can lead to a user having 3 sites setup in 3 different apps. It can become a mess very quickly.
- archerx 2y agoOr this stupid flow needs to die.