4 ms·
Email OTP is garbage without the option to also add a password. That just outsources the problem to the user's email service, and assures that compromising the
by Plont 25d ago
Email OTP is garbage without the option to also add a password. That just outsources the problem to the user's email service, and assures that compromising the email inbox alone is enough to immediately also compromise every service that uses passwordless, 2FA-less "magic link" or OTP login.
Email services don't even support true 2FA; many claim to, and ask for a 2FA code for web login, but connecting an email account to a client via POP or IMAP bypasses that.
- toomuchtodo 25d agoI implement customer identity and access management for millions of users in financial services, based on requirements driven in part by US federal regulatory and cyber insurance requirements. What’s your experience? > Email services don't even support true 2FA; many claim to, and ask for a 2FA code for web login, but connecting an email account to a client via POP or IMAP bypasses that. "In less than a year, passkeys have been used to authenticate people more than 1 billion times across over 400 million Google Accounts. Passkeys are easy to use and phishing resistant, only relying on a fingerprint, face scan or a pin making them 50% faster than passwords. In fact, on a daily basis passkeys are already used for authentication on Google Accounts more often than legacy forms of 2SV, such as SMS one-time passwords (OTPs) and app based OTPs (such as Authenticator apps) combined." https://blog.google/innovation-and-ai/technology/safety-security/google-passkeys-update-april-2024/ https://blog.google/innovation-and-ai/technology/safety-secu... (April 2024) Don't forget: Microsoft is killing passwords. How to set up a Microsoft passkey before August deadline. - https://mashable.com/article/microsoft-passkey-how-to-password-deadline https://mashable.com/article/microsoft-passkey-how-to-passwo... - June 20th, 2025 (All major email providers support either passkeys, or in the case of Microsoft, passwordless ["strong authentication"]; we can consider the user creating an app specific secret for an external mail client minimal risk if performed after strong authentication has occurred, as the odds are low of that secret being phished or exfiltrated once configured in their mail client of choice, for the few folks interested in such a user experience with web based email services)
- cozzyd 25d agoBut passkeys are not supported natively (i.e. without a USB key or other shenanigans) by Firefox on Linux, as there is no place to store them. I do have a USB key, but it's annoying enough that I don't like passkeys if I can avoid them (instead using long randomly-generated passwords by Firefox's builtin-in password manager). Maybe Lennart needs to write systemd-passkeyd .
- toomuchtodo 25d agoI admit this is a gap, but this use case is a rounding error at the scale of users and daily logins. If someone wants to fix this, drop a link to sponsor the time and tokens needed to enable native support. Does a Yubikey or secure authenticator work for your use cases currently?
- cozzyd 24d agoYes, a yubikey works for when I really need it, but it's enough friction to take out out and plug in that it's just annoying enough.
- toomuchtodo 24d agoI'll talk to some industry folks and see what we can do.