12 ms·
Are there benefits to append the token to the end of the password over adding a field for it in the form?
by mariusz331 12y ago
Are there benefits to append the token to the end of the password over adding a field for it in the form?
- thesimon 12y agoConvenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated. Not saying that this is a good idea, but there are some benefits for appending the token.
- jeremyt 12y agoI might buy it if two factor activation wasn't a one time operation. As it stands, there's no need to confuse existing users. You just need a separate pathway to activate the token. THEN you just ask for the token as a step two in the login process. That's actually how Schwab handles things right now.
- markcerqueira 12y agoFor some shitty services, like PayPal that don't give you a long-lived auth token, it is an every-time process. :| As expected, Schwab isn't the only perpetrator of bad two-factor auth. I think PayPal still DOES NOT support two-factor auth on their mobile clients. Shameless plug of my blog posts about Paypal's terrible two factor auth: http://mark.gg/2014/10/22/paypal-and-delusions-of-grandeur/ http://mark.gg/2014/10/22/paypal-and-delusions-of-grandeur/ http://mark.gg/2014/06/04/kicking-the-tires-with-paypal/ http://mark.gg/2014/06/04/kicking-the-tires-with-paypal/
- markcerqueira 12y agoDefinitely not more convenient for users in all cases. LinkedIn did something similar. When they told me to append my code to the end of my password and I click on the password field, my password would be wiped away so I'd have to type in my password AGAIN and then add the security token to the end of it. You don't need a third field. On mobile, if you pass the password auth, you go to a new screen and bring up a number pad and ask the user to wait for the text message. It's pretty smooth. Much smoother than the LinkedIn flow I described above. If you don't have 2-factor auth after passing the password auth, you just go right to the app. I documented my frustrations here in case you want to see: http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication/ http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication... LinkedIn already fixed this, but it's quite shameful they even let this out into the wild. :/
- michaelt 12y agoIf they're going for "less complicated" then what they've done hasn't achieved it :)
- markcerqueira 12y agoIt saves client engineers some small amount of time from implementing it on their end, but building these screens shouldn't take more than a few days. It's a terrible UX though. I wrote a blog post with some images about it if you want to see what it looks like: http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication/ http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication...