4 ms·
This is an interestimg idea and surely has it's place, but how you implement it is critical. For example, you would want SSL for the entire site to ensure the c
by m8urn 14y ago
This is an interestimg idea and surely has it's place, but how you implement it is critical. For example, you would want SSL for the entire site to ensure the cookie is always protected. You would also need to make sure that the token and session management is solid.
Of course to really make it secure, you would want all smtp connections between you and the user to use SSL, which you cannot guarantee. One test I always use for new authentication schemes is would the NSA be able to compromise your account if they wanted? In this case I would definitely say yes.
Still, this would be excellent for sites that only have you login to set preferences, etc.