3 ms·
I'd recommend expiring the link after a single use. A password-less login essentially trades something you know (a password) for something you have (a link). Th
by dbyler 13y ago
I'd recommend expiring the link after a single use. A password-less login essentially trades something you know (a password) for something you have (a link). The security of a passwordless system depends on the security of the link... so if it expires once it's been used (which will usually be immediately), the risk associated with the link drops. This also prevents replay attacks.
I'm assuming your site's sessions are longer than the timeout of the sign-in link, so most users won't need to sign in multiple times in a short period anyway.
Also, a couple related links, if you haven't seen them:
http://notes.xoxco.com/post/27999787765/is-it-time-for-password-less-login http://notes.xoxco.com/post/27999787765/is-it-time-for-passw...
https://nopassword.alexsmolen.com https://nopassword.alexsmolen.com