Automatic Login Links
collectiveidea.com
collectiveidea.com
Furthermore, when offering direct login links you are training your users to not remember their passwords. A bad side-effect, unless you have only users who will never login except when notified.
Come to think of it, that sounds very convenient. How about a security model that links an account only to an email address? This implies that anyone who can read that email account can log in. For many purposes, this might be fine.
You could do without those nasty passwords entirely then. Logging in from a new computer without cookies stored means having yourself a new "log me in" email sent. Sucks if you have to open your email just for that, but then again, for some services, this might seldomly be a problem because of their email-oriented nature.
Isn't Google Authenticator supposed to have an open API so that any service can give you a secure seed and then let you use your mobile phone to login? https://code.google.com/p/google-authenticator/
If you are comfortable with that, great. Provide this feature as a nice option. However, if your service hosts any sort of sensitive information at all, or has anything to do with money, please don't turn this on by default. This is one step away from send me my password in clear text.
Introducing some sort of security questions helps a bit, depending on implementation. Another idea would be to ask the user to create a temporary PIN, that is then used to sign the token, and is asked for again, when the user actually clicks the emailed link.
Lastly, users are more or less trained not to forward password reset emails. However, getting an email that says "Your stock is burning, click here to sell all." might cause the panic-stricken user to forward this email to his/her broker.
Most of the farmers in my extended family are quite intelligent people, many of whom have masters degrees in agriculture.
If instead of "farmers" it said "women" the author would likely get flogged.
That said, there's a lot of good points in this article. SSL wrapping the entire thing so that the autologin URL didn't go over the wire in plaintext would be the obvious next security step.
It's possible he's way off on that assumption, but I would say devoid of data it's a fairly safe one.
I'm sure you could find quite a few insulting fill-in-the-blank nouns.
Farming in western coutries these days is about running lean and highly automated businesses on tiny margins. Virtually all professional farmers are comfortable using computers and specialized software.
That's nice, but are they adept computer users? I know plenty of very intelligent people who haven't needed or bothered to learn how to use a computer well. Stop seeing slights where they aren't happening.
You can find more details here: http://en.wikipedia.org/wiki/Capability-based_security
Don't get me wrong, the code and implementation brings something to the table on it's own. I just think the original author should get some attention too.
Of course, it does have a couple of disadvantages (not all users have Facebook/Twitter accounts or would feel comfortable with you having access to them, plus you're partially dependent on an external service), but I think for most applications SSO would be preferable to authentication tokens.
Another attribute that I would assume of "less adept computer users" is that they usually use the same computer for all their tasks. Again, I'd be interested to learn if the "forgot password" link is used less as more browsers are seamlessly integrating password remembering features.
The one time use link is a nice trick and would be glad it passes the snake oil check because it provides a significant simplification.
What happen if they loose the link ? What would be the damage if the link gets exposed or stolen ?
I agree, though.
Hey, guess what my mom does.
Automatic login links have the same issues, but them some more.
Please remember people WILL forward emails. This means that people WILL have unauthorised access to your system.
If you are implementing the system as you have described, you are being negligent to your users. You are also setting yourself up to be the next Sony.