6 ms·
When you enter your e-mail, you receive a message such as... --- Log into The Magazine by opening this link: https://the-magazine.org/login/8LvjumLKwNXeBX2zD
by Anonymous09 14y ago
When you enter your e-mail, you receive a message such as...
---
Log into The Magazine by opening this link:
https://the-magazine.org/login/8LvjumLKwNXeBX2zDkxZGuDixUzds01SAwlUPksK https://the-magazine.org/login/8LvjumLKwNXeBX2zDkxZGuDixUzds...
This link will expire after an hour and can only be used once. To log into multiple browsers, send a login request from each one.
---
It works well, they click the e-mail link, and it saves a cookie to log them in. I think it's a decent solution. It comes down to preference, would you rather type in a password, or click a link e-mailed to you. At times, I have complex passwords, so they take a while to type, and other times, I'd rather type in a password, than access my e-mail on a computer or network of questionable security.
In the end, passwords need to change, and I think in the future they'll disappear. We need smart cards or something along those lines. Click the login button, pass the card over your phone or computer, and you're instantly logged in. The card remains in your wallet like any other.
- ypeterholmes 14y agoI'm missing something. What happens when you come back?
- mjschultz 14y agoI would assume the cookie is still valid and you're authenticated, or you type the email address and you get a fresh token.
- Anonymous09 14y agoIt would be based on cookies, no different than logging in with a password, then returning at a later date. Instead of typing a password, you click an e-mail link. That's the only difference, and like I said, it comes down to preference. A number of people have said it provides weaker security, but I disagree. You can guess passwords, you can record or watch someone type a password, or catch the password over insecure protocols. The e-mail approach doesn't have these holes. The link is valid once, so if you login and someone else tries to use the same URL after snooping, it's not possible. With password logins, people can use the password for that site, or your e-mail password to reset the login. With the e-mail method, they need your e-mail password, that's the only way they'll be able to login to your account. However, you do need secure access to your e-mail. I know there are times when I'm on a public or friends computer, and I need to quickly login to a service. I'd much rather enter my password only used on that service, instead of entering my e-mail password. This way, if it becomes compromised, it would be a much smaller concern.