E-mail Sign On
peej.co.uk
peej.co.uk
2. go to e-mail
3. refresh
4. refresh
5. count to ten... refresh again
6. maybe it's in my spam folder?.. no...
7. final refresh
8. give up in disgust
minutes pass
9. e-mail finally arrives in inbox; delete it
----
I effectively use this method to log in to Amazon (I have a habit of always changing my Amazon password to something so secure I can't remember it for more than a minute at a time), and it makes me less likely to log in (I want to add this book to my wishlist, but I have to log in first? Maybe I won't bother then).
To be fair Amazon password reset e-mails are usually in my inbox by the time I switch to my e-mail, but some sites are slower.
An existing example: when you recover a password for some service you do it because you want to log in NOW, not some time next week.
Apparently simple to implement for both customer and provider and takes alway all the headaches from account registering.
I would pay for that.
A visitor wants to use one of our request forms so he enters his email address and clicks Submit. The next page says "Check your inbox, spam and junk mail boxes for the email we just sent you, then click the link to complete our request form."
Nearly all of them click the link. SPAM and bogus requests have dropped to zero.
Once in a while we get a complaint stating that they never received the confirmation email, but we know they were all sent because we BCC copies to a special gmail account for archival purposes.
The client is happy.
No, this is not a login system but I'm going to implement it on my new website as a login system because it is MUCH simpler than dealing with passwords ... and there is far less resistance to this system than some of you seem to be complaining about.
The fact is, people really dislike dealing with passwords and this system gets rid of them.
Hm, might become too inconvenient. The only advantage would be not having to remember the password.
This makes me think the traditional password recovery mechanism should also work that way. You should have to enter your new password first, then get the confirmation link to save it.
Some of the OpenID crowd were aware of it at the time, but it hasn't really caught on. It's kinda fun to use it as an OpenID provider to log in to itself. Very meta and clean.
If I'm on an untrusted (potentially keylogging) computer, I don't want to type my email password - but I may not care about the security of my Pandora password.
I think the process is defaulting every site to the same trust level as your email.
Definitely adds more resistance to the flow.