Bye Bye Passwords
blog.shopittome.com
blog.shopittome.com
(Seriously, that's a question: Why don't more people use OpenID? Is there something wrong with it?)
Because the user is more likely to have email than OpenID, so delegating to an option of one or the other is more complex, and delegating to only the latter is limiting your market.
But yeah, I guess saying "now go to this 3rd party website and create an OpenID account" is pretty ugly. I wonder if it's possible to have your own "sign up" page that's a proxy for creating an OpenID with a 3rd party provider?
People are likely to remember their email if they have one, but URLs are disappearing from user interfaces (see Chrome, Safari, Mobile Safari, etc.).
A user probably already has email, thus it usually isn't required. Unlike openID
They do seem to moving towards OpenID Connect though, which is just a identity layer on top of OAuth 2.0
Issue 2: tech-phobic people don't trust OpenID, OAuth, etc. I'm working with a client who wanted "single sign on" with a tolerated competitor in the same space (nonprofit, don't ask); that competitor's tech guy advocated for OpenID, and OpenID became a hard requirement. The problem: the client's membership fought tooth and nail throughout alpha & beta rollouts (change is scary. are we giving google/yahoo our information? we don't understand it. we're not a bank, why do we need tighter authentication? etc) and it was eventually scrapped in favor of a traditional login.
(I don't know about you, but I can't think of anything more distracting than my email inbox.)
I know it's not popular on HN, but we already have a simple method that removes passwords: OAuth.
What is the risk though? If someone did steal your one time link and get into the app could you somehow prevent them from continuing to access it? And what could they do in the app -- change your address and buy stuff on your credit card and send it to themselves? Feels like there is just some tiny level of risk here that probably wouldn't happen... but I wouldn't feel completely safe with this.
Even if you have the most secure password in the world, if an attacker compromises your email account, they can simply send a password reset email. It's the weakest link.
[0] https://github.com/handshakejs [1] http://vimeo.com/90883185
Drop the email field altogether and you might have something refreshing.
I think my attention time out for this would be 30-45 seconds.
Why not allow Apps to not use passwords in this case?
In addition (for me) the app would be on my mobile, which is passcode protected (and fingerprint). Beyond that security you have full access to my email anyway, so what's any additional app password going to provide?
since you need the device (which you're presumably steeling) AND the passcode for it, does this make it 2FA? I think I've read Apple claim as much in a Data Protection document, but I wonder whether you can really count the device you're trying to log in TO as one of the Factors?
I am just talking generally, not specific to this app
From a compliance standpoint (ignoring security feature), would this be allowed?
From a security standpoint, not sure this is any better/worse than social login or receiving an SMS. Most of the time you have all these portals (including email) already authenticated so it doesn't really make a difference which you use. The nicety is that you can basically track your logins through email which is pretty neat.
From a usability standpoint, I feel like an SMS would make more sense? I turn off push notifications for email because I receive too many, but I'd be able to read the number from the text and type it in right away (assuming that you'd use standard MFA tokens). Maybe the difference is more between using a 6-digit PIN instead of a link than the source it's received.
"Why do you need people's name and email? The above screenshot looks like an APP. You already have a way to reach them: in-app notifications. And why do you need their name until they purchase something?"
But ironically, the resulting page said "Please enter correct password. Spam free wordpress." LOL
As for name and email -- Shop It To Me is not just an app but also a website and email service and so we need a way to link them all together. If we did not have an email and the member lost their phone, they'd lose their account forever.
People have to opt-in to in-app notifications. If they press no intentionally or accidentally, recovery is far, far more difficult. Email is much easier and more controllable than notifications.
True, but not for the user. I would much rather accept notifications than type in my email address. I avoid the risk of getting spammed, don't need to decide what email to use, don't need to decide if I trust the developer. And with app notifications, the ability to unsubscribe is much more consistent and reliable.
Do we end up with a system that's of equal or higher safety?
Agreed that convenience is definitely up, since we have email clients built into everything.
That being said, for sites this that are more concerned with "verification" than "authentication" this seems like a viable approach.
What I learned from FtC is that people are so ingrained with the idea of passwords that single factor auth doesn't really fly.
Passwords are still widely used, and for good reason. I partially accept your point of passwords not being very secure, but why not just spend some time implementing a 2FA login method, instead of this?
Appreciate what they're trying to do, but I think this is a bad idea.
edit: As tootie points out, it would be possible to use a "whitelisted" company.
this option only makes sense if email delivery can be guaranteed to be secure, and the recipient has non-password-based (two factor) auth.
That doesn't sound very safe. Does this use some form of OTP that's passed via a special URL that only works with the mobile app? If so that sounds better than what I'm thinking.
The article says that it's a one-time link, so I assume that means that the same link can't be used twice. If someone had access to my email, they'd have to use that link before me, which is a very small window of time (submitting the form in the app and then opening an email, ~15 seconds tops).