3 ms·
Unless I'm misunderstanding something, if someone has access to my email they can just login right? That doesn't sound very safe. Does this use some form of O
by calebio 12y ago
Unless I'm misunderstanding something, if someone has access to my email they can just login right?
That doesn't sound very safe. Does this use some form of OTP that's passed via a special URL that only works with the mobile app? If so that sounds better than what I'm thinking.
- fishtoaster 12y agoWell, that's true of most services, right? If they have access to your email, they can just click the 'reset password' link on a site and use the resulting email link to log in.
- ori_b 12y agoI don't know how it works, but I hope it generates a private key/public key pair, and uploads the public key. Kind of like SSH authentication.
- andrethegiant 12y ago> if someone has access to my email they can just login right? The article says that it's a one-time link, so I assume that means that the same link can't be used twice. If someone had access to my email, they'd have to use that link before me, which is a very small window of time (submitting the form in the app and then opening an email, ~15 seconds tops).
- arthens 12y agoOr, you know, just request a new login link, use it and delete the email. If they are fast enough you won't even notice the notification on your phone.
- jamesjyu 12y agoIf someone has access to your email, most all of your internet accounts are going to be in grave danger.
- monkeynotes 12y agoIf someone else had access to my email I'd have bigger problems than my shopping app being compromised.