Show HN: No More Passwords, Just Email
nomorepasswordsjustemail.meteor.com
nomorepasswordsjustemail.meteor.com
If not, this might be a good second option for a site to have that doesn't involve you resetting your password:
First option - normal password Second option - email one-time key Third option - reset pw via email (if you really need to)
Any accounts that are accessed on other people's computers should be unimportant (e.g., email accounts that aren't associated with financial accounts) because those computers could be compromised. Unimportant accounts don't require strong passwords, so a password manager isn't needed for accounts that one might access on other people's computers.
It's much much faster than opening my email, and waiting for SMTP & Gmail to get its act together.
I'm okay with this.
Does Gmail now support 2FA? The last time I checked, Gmail supported Google's 2-Step Verification. 2SV includes backup codes, which cause 2SV to be 1FA:
Password + Backup Codes = Something You Know + Something You Know = 1FA
I will be a very happy person when / if I see a persona login page on more sites
Here is a great video about it: https://www.youtube.com/watch?v=nJff23UdNAI
If you have not heard of Persona, or have heard of it but don't see what the big deal is / why it's different to "Login with google", "Login with twitter" etc, then go watch this video. It is a very elegant, decentralised solution to the login problem.
https://developer.mozilla.org/en-US/Persona/Protocol_Overvie...
As a proof of concept, I couldn't actually get your site to work because by the time I understood the UI flow, it was throwing an alert saying "Error with that email address". Also, this goes to spam for me... just to let you know.
I'm thinking of adding a log-in link to the email, in addition to the 5-digit code, for people that prefer that method. That way they'd have both options in the same email.
Also, I really would try to smooth out the login flow even for a POC. If I accidentally enter an old code (even if it's 5 minutes) it won't let me in. That seems OK. However, what happens next is I copy the correct/latest code, but the UI asks for my email again to send another code. When I paste in the code I have copied, it's invalid yet again.
In a nutshell: "In most cases you won't need to do this often" is a HUGE fallacy. It depends on the security rules you work/live by. Plus, it would make it really annoying to use if on top you're using TOR.
Yes, passwords need to be fixed. They are weak, problematic and a security cheddar cheese. It is why we are now implementing two factor authentication. Changing the "fixed password" strategy to a "random and time limited password" strategy isn't exactly solving more issues than it raises. Again, from a security-wise stand point.
May be if this was implemented with something different than your email. Like, for example, a bank tokens or cell phone verifications... which, again, are part of a two factor authentication because by themselves they would be too easy to break.
Think about the following scenario: You use X site with this email auth system and, for example, Thunderbird. Stand up and go to the bathroom or a meeting or whatever without locking your computer. Presto! I won't even need to guess a password and get access. Of course getting access to X site would be the least of your worries in that example, but it illustrates the point I'm trying to make.
You are not increasing security, whatsoever. You are setting all the security in an email service, which we already know are not the most secure services at this moment.
May be, such login can be applied inside a company's network, where you have control over the security of the servers, certificates, network encryption, etc.
Now if you think about it from a social engineering perspective. It is much easier to get access to a single email account than to every account you own. And about persistence of access... There's this thing called email forwarder. If I get access to your email, I would create a forwarder for all the email you receive to one I control; chances are you won't notice it in a long time.
Imagine e.g. problems with your DNS (self-hosted and you forgot to renew the domain), outages of your mail provider, or the worst case (for the service provider): your outbound mail server is placed on a blacklist.
This way your entire user management system goes up in smoke without ANY way for you to fix it!
Using email login links instead of passwords doesn't seem especially worse wrt. security than "industry standards".
As for the other stuff (DNS, outage), it is a much bigger deal to loose these than an account at a 'nice to have' social website.
But this coupled with two factor authentication to recognise new computers is a nice idea.
If my webserver or worse, my domain, ends up on a spam blacklist, either due to moronic/malicious users flagging my mails as spam or due to automatic triggering running amok, then I have no way of ever getting my sign-in working again except of praying that the blacklist manager(s) will unblock me. Which rarely happens.
This is the perspective of the service provider. From the user POV, if their domain gets blacklisted, they can still receive emails, and therefore can still login as usual.
HN thread here: https://news.ycombinator.com/item?id=4570600
It's a great concept, but like any new authentication mechanism there's a usability and security cost due to the lack of familiarity.
Plenty of authentication mechanisms are "better" than passwords, but passwords are well-understood and flexible, which is a huge advantage for almost all sites.
For that reason alone I don't see how only using email verification as a low-friction way to log in makes sense.
I really don't consider email nearly reliable enough for any important logins.
It might work if I have a password in my password manager as a fallback, but then just using the password manager would be the way to go.
Edit: Actually this could work as the fallback for if I for some reason don't have access to the password manager, so I might use it but not for the intended purpose.
That said, please use Mozilla Persona instead.
For example, setting an email forwarder to an account an attacker controls in most cases won't even be noticed. I think it opens more attack vectors than the good it could do to have this kind of integration rather than just a password manager.
Giving more control to a single manager (in this case an email account) also means you will have to set greater security standards for it. For example, are you going to type your password (which also controls all your accounts) to your friend's, school's, airport's, etc's computer that could be infected?
Passwords are insecure? Of course they are insecure. That's why we are trying to implement two factor authentication. But having 1 account with 2 factor auth controlling 20 accounts with 1 factor auth isn't exactly helping. At all.
Setting a forwarder where? You can do that now too. It's exactly as safe as what we have now.
> I think it opens more attack vectors than the good it could do to have this kind of integration rather than just a password manager.
I disagree. As long as you have password resets sent by email, whoever has access to your email has access to your accounts.
> Giving more control to a single manager (in this case an email account) also means you will have to set greater security standards for it.
Again, that's exactly what everyone already does.
> For example, are you going to type your password (which also controls all your accounts) to your friend's, school's, airport's, etc's computer that could be infected?
No, I don't log in to my email from anywhere that's not my device, and it has 2fa enabled.
> having 1 account with 2 factor auth controlling 20 accounts with 1 factor auth isn't exactly helping. At all.
How is it not helping? Now you have all your accounts requiring two-factor auth to log in, rather than just some of them. You also only have one server to secure, which will presumably be run by people whose sole job is to secure that server.
>How is it not helping? Now you have all your accounts requiring two-factor auth to log in, rather than just some of them. You also only have one server to secure, which will presumably be run by people whose sole job is to secure that server.
Yes, you are left with only one server to secure, and yes it is most likely run by people who are good at it. But this is exactly why it's a good example of candy security: As soon as you get past the first wall, there is nothing else stopping you from getting access to everything. And you can't really presume all users will have double auth activated, nor that they will be as cautious with that single set of credentials will be.
This is the question I'd like you to address: How is it less secure than what we have now?
Flask-Security looks like a good solution to every new web site having to roll their own code. BTW, It's not clear from Flask-Security that there is a no-password option given that the user model has a password field required.