Live data from Hacker News

Are Magic Links Outdated?

zitadel.com

1–10 of 230 posts

Re: Are Magic Links Outdated?

#3
I've been thinking about magic links using QR codes rather then email.

EDIT: The idea here is that on a device where you're already logged in you generate a QR code, you photograph that code on another device, and then you confirm on the first device that it's really you who photographed the code on the other device.

Re: Are Magic Links Outdated?

#4
post #2

They don’t seem that outdated to me, given the evidence presented. email provider security is a real problem but is usually considered the root of trust for persons…

Also a possible way for magic links to be secure even if email is compromised is for the requesting browser to create a secret client side so that only that browser can actually proceed with the magic link.

Re: Are Magic Links Outdated?

#5
Article fails to mention that "Magic Links" are not only possible via email, but any out-of-band method, so you could use Whatsapp, Telegram or IRC even. Obviously, the user is assumed to have a secure setup regarding whatever method you send the link via.

Which the "Email Security" section kind of hints to as well, that it's important users have a secure email setup. What they fail to mention, is that this is important not only if you use "Magic Links" but also if you have username+password login with "Reset my password" functionality, as otherwise intruders will be able to change your password anyways.

In conclusion, the article seems to have been written with the goal of saying "Everyone is using Magic Links, how can we get them to use Zitadel (their product) instead?", rather than an honest look on how "Magic Links" can be made more secure.

Re: Are Magic Links Outdated?

#6
I hate them. Force me to go to my mailbox while I have a good password manager and just want to use that instead. I get the idea, but this should be an alternative, not a default. Also sends loads of single use emails that will remain for ever in users mailboxes.

Re: Are Magic Links Outdated?

#8

I've been thinking about magic links using QR codes rather then email. EDIT: The idea here is that on a device where you're already logged in you generate a QR code, you photograph that code on another device, and then you confirm on the first device that it's really you who photographed the code on the other device.

I don't understand. What would the QR encode? Surely not the magic link itself, as that would defeat the purpose.

Re: Are Magic Links Outdated?

#9
post #4
post #2

They don’t seem that outdated to me, given the evidence presented. email provider security is a real problem but is usually considered the root of trust for persons…

Also a possible way for magic links to be secure even if email is compromised is for the requesting browser to create a secret client side so that only that browser can actually proceed with the magic link.

If the email is compromised, the hacker can just go to the front page in their own browser and generate a fresh login email, so there's no extra protection in client-side browser secrets.

Re: Are Magic Links Outdated?

#10

I hate them. Force me to go to my mailbox while I have a good password manager and just want to use that instead. I get the idea, but this should be an alternative, not a default. Also sends loads of single use emails that will remain for ever in users mailboxes.

If it's magic link or multi-factor authentication, I know which one I prefer. Try explaining to an MFA-loving service that your phone is out of action while it's being repaired.
Post reply on HN