9
12 Comments

Drop passwords.Use magic links.

https://magic.link/
submitted this linkon June 26, 2020
  1. 9

    Every time I see a product using it my interest goes to zero. It's so annoying having to open my e-mail every time I want to login. Why not just use Google since they have 2FA, etc, and in the end is the same layer of security without the annoyance.

    1. 1

      Using only email links for auth is annoying because it's much slower than logging in with 1Password. But, I'm ok with email links in addition to email+password auth.

    2. 1

      If use app often then it can be a rolling login, no? Only re-authenticate if not used for a while.

  2. 2

    Good God, no. I hate magic links with every fiber of my being. If you want to offer it as an option for people who think it's fun to switch tabs in the middle of logging in, then click a link that opens an entirely NEW tab and have to close the original one, I guess whatever.

    Strong password requirements + non-SMS 2FA, plz.

  3. 2

    Nooooo!! They suck. I’ve actually stopped using services because they do that!!

    1. 1

      If daily then yeah pain. But if rolling so you only do it when you've not used the app for a while then why not?

  4. 1

    I wouldn't use this particular product, but I can say from personal experience of using on-boarding links within email, that they definitely reduce friction for bringing users into your web portal for the first time. Then, if they decide they want to stick around they can make an account with login and password and get the extra permissions and features.

    (I'm not a security expert, and don't claim to understand all the risks of on-boarding links vs. alternatives.)

  5. 1

    It makes products impossible to use when I want to access them on my work laptop and the email goes to my personal laptop / smartphone. There is much better ways to login, I guess...

  6. 7

    This comment was deleted 4 years ago

    1. 1

      If daily then yeah pain. But if rolling so you only do it when you've not used the app for a while then why not?

      1. 1

        It's still very annoying. And honestly, it's not much safer than using passwords.

    2. 1

      This comment was deleted 6 years ago

  7. 1

    This comment was deleted 6 years ago

    1. 1

      Email is insecure. SMS is insecure. Passwords are insecure. Face Id is 1-in-a-million insecure (less for siblings, 5 attempts, reverts to passcode - which is 1-in-10k insecure). Touch Id is 1-in-50k (assume same fallback). What's not to love about authentication?

    2. 1

      What would you like to see? I'm interested?