3 ms·
Although they say it is a "one time password" which is smart, email is still assumed to be not secure. Like for example, you wouldn't want to send your SSN thr
by benferris 12y ago
Although they say it is a "one time password" which is smart, email is still assumed to be not secure. Like for example, you wouldn't want to send your SSN through email because servers along the way can possibly sniff it. So, while it seems safe in most situations to do this, I feel that it probably isn't 100% safe but maybe good enough for most people.
What is the risk though? If someone did steal your one time link and get into the app could you somehow prevent them from continuing to access it? And what could they do in the app -- change your address and buy stuff on your credit card and send it to themselves? Feels like there is just some tiny level of risk here that probably wouldn't happen... but I wouldn't feel completely safe with this.
- RaphiePS 12y agoThe way I see it, every single app that uses email for password resets (usually by emailing a link, sometimes a code) already relies on the security of email. Even if you have the most secure password in the world, if an attacker compromises your email account, they can simply send a password reset email. It's the weakest link.