Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Better yet, don’t use passwords at all. I’m personally fond of the magic link sent to email method of authN


This doesn't work well if you aren't working in your default browser and if the link expires after a single use. For instance, if you're trying to log into an app (not a website) and the redirect to the app doesn't work when you tap the link in your email.

I suppose an alternative approach would be to open a websocket in the post login page, and if you open the link in your email the server sends your browser a cookie or something, and then you're in. But I've never seen that approach.


I'm the opposite. I deliberately avoid checking my email outside of predefined times, and hate it when a website assumes that everyone is happily living in their inbox.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: