3 ms·
I wish websites with user accounts would offer the option to "login via email" - as in you'd type in your username (or preferably your email) and maybe a captch
by FaceKicker 14y ago
I wish websites with user accounts would offer the option to "login via email" - as in you'd type in your username (or preferably your email) and maybe a captcha and then you'd login by clicking a link it sends via email afterwards. Ideally having a password associated with the account at all would be optional.
I have a Gmail tab opened just about 100% of the time I'm on the computer, so this would be very convenient for me as an alternative to having to remember passwords for sites that I visit once a month or less (and end up having to get a "password reset" link via email every time I log in anyway), and then I'd only have to keep my Gmail account secure (which I do via 2 factor).
- yen223 14y agoIn this case it wouldn't have helped, because the intruder apparently had access to a Dropbox employee's email account. EDIT: Disregard what I said, apparently the attacker had access to the Dropbox employee's Dropbox account.
- FaceKicker 14y agoTo be honest I was mostly using the comments section for this link as a soapbox, I realize the idea isn't too relevant to this particular case with Dropbox, as no passwords are known to have been revealed. Sorry. Though, I do think it would often mitigate the damage from this type of security breach that it seems like we've seen so much of from big name tech companies lately. I'd guess that a majority of accounts created on the internet are pretty unimportant to the account creator, and with how often passwords are reused indiscriminately, the worst effect of these password leaks is often not the unauthorized access to all those accounts on the hacked site but rather the usernames and passwords themselves - which are very often reused for bank, email, etc. accounts. With my proposal, anyone who opted not to have a password wouldn't be vulnerable to that.
- tlrobinson 14y agoWhere do you see anything about the Dropbox employee's email account being compromised?
- yen223 14y agoYou are right, I misread. Thanks for pointing that out :)
- mike-cardwell 14y agoIf somebody managed to get read access to my email account, they still wouldn't be able to read any email sent to it - https://grepular.com/Automatically_Encrypting_all_Incoming_Email https://grepular.com/Automatically_Encrypting_all_Incoming_E...
- ajasmin 14y agoHaving your webmail service also act as an OpenID provider would be much simpler. I often login with Gmail (or rather my Google account) on sites that support it.
- drivebyacct2 14y agoOr a protocol built for that that doesn't rely on DNS names instead of what you're talking about tying the identity too :) BrowserID.
- StavrosK 14y agoThat's exactly what http://www.yourpane.com http://www.yourpane.com does. I thought it was pretty convenient, but it turns out most users expect a username/password. However, it fits the service's model well, so it works out in the end for YourPane.
- bradleyland 14y agoThe trouble with that solution is that email is not an instant protocol. It's usually instant, but SMTP RFCs give mail servers up to 72 hours to deliver before they must send back a delay notification. We use Google Apps to host our email, and I've seen plenty of occasions where their systems don't deliver mail immediately. This "issue" used to generate a lot of calls when I was doing freelance consulting. "Bob sent me an email over 20 minutes ago and it's still not here." I'd get those calls all the time. Imagine you're trying to get logged in somewhere and you have to wait an hour or two for an email to show up.