5 ms·
To add a couple other thoughts off the top of my head: Your login link now passes through one or more third parties (SMTP servers) which may or may not use TLS
by oops 7y ago
To add a couple other thoughts off the top of my head:
Your login link now passes through one or more third parties (SMTP servers) which may or may not use TLS, and which may or may not have their certificates validated by each other. So technically a targeted MITM would be possible that would not have been possible with a normal HTTPS password authentication.
Also from a privacy standpoint, your email host and any relays involved now have a detailed record of every time you logged in.