Magic: A Key-Based Authentication System for Self-Sovereign Identity
go.magic.link
go.magic.link
Also in the whitepaper, I saw this:
> To ensure Magic cannot decrypt the encrypted key for redundancy, we have removed our permission to decrypt with our KMS instances.
I don't know too much about how KMS works so I apologize for my naivete but what's to say you can't give yourself back that permission?
It's actually possible to lock ourselves out as the root user and not be able to change the permissions!
I have a question on the main product - doesn't pushing the link to email just pass the password breach potential to the email provider?
definitely understand the reduction of attack vectors but does it not consolidate the risk?
And to think that I was so hopeful... up until I read that.
We'll work on a documentation on this and also feel free to reach out to us at hello@magic.link in the meanwhile. Would love to learn more about your use case and explore how we can help you migrate!