Earlier quoted context omitted.
Oh the few websites that do this drive me absolutely crazy. It makes me immediately look for alternatives, it's unbearable
Revolut does this for app logins and it's infuriating when your (new) phone doesn't have the email account used synchronized.
Why don’t we do email verification in reverse?
311–320 of 329 posts
Re: Why don’t we do email verification in reverse?
#312Earlier quoted context omitted.
Most webapps have a need for transactional messaging of some sort. But even putting that aside you’re missing TOS support. Every TOS is going to have conditions that define scenarios where you need to communicate with users. Including changes to the terms of service ;-). Or for breaches of data, you’ll want/contractually need to communicate that to your users. So yeah you could build different options for all of thes…
Good point about TOS, that's indeed an important use case. However usually TOS declare that it is a responsibility of the user to keep up with changes. Good service providers also say they will make a reasonable effort to inform the user about the changes. So the TOS update notifications is not a complete blocker for my approach. What do you mean by transactional messaging? Could you give an example?
1. receipt / shipping notifications from an online shop 2. emails from enterprise chat apps that let you know you’ve missed messages 3. “Suspicious login” or similar notifications 4. prompts about billing if credit card is nearing expiration or a problem charging your account
Re: Why don’t we do email verification in reverse?
#313Earlier quoted context omitted.
Email can replace only the password, leaving you with 2FA still. Another messaging channel is fine of course. You could replace email address by a phone number for SMS/WhatsApp/Signal. Is that more secure though? Would a user rather give your random app their phone number than email address? Secret questions are usually very much not secret (less safe than password). They are way easier to uncover about a person, and…
> Another messaging channel is fine of course. You could replace email address by a phone number for SMS/WhatsApp/Signal. Is that more secure though? Would a user rather give your random app their phone number than email address? Yes! Even insecure SMS is more secure than email. You know why? Because everybody and their mother is logging and inspecting email, I see people's reset codes and links all the time to every…
> I think you skipped over parts of my post
> "I refuse to change" is what you are saying
> you can think about this longer than a minute
> if you read my comment before replying
Why are you so hostile? Why use an online forum at all if you will attack anyone engaging with you?
You do have some good points there, but is this really the only way you are capable of expressing them?
Re: Why don’t we do email verification in reverse?
#314Earlier quoted context omitted.
Good point about TOS, that's indeed an important use case. However usually TOS declare that it is a responsibility of the user to keep up with changes. Good service providers also say they will make a reasonable effort to inform the user about the changes. So the TOS update notifications is not a complete blocker for my approach. What do you mean by transactional messaging? Could you give an example?
Non-marketing emails from the company to push information to you while you’re out of the app. Think stuff like: 1. receipt / shipping notifications from an online shop 2. emails from enterprise chat apps that let you know you’ve missed messages 3. “Suspicious login” or similar notifications 4. prompts about billing if credit card is nearing expiration or a problem charging your account
Re: Why don’t we do email verification in reverse?
#315Earlier quoted context omitted.
> Another messaging channel is fine of course. You could replace email address by a phone number for SMS/WhatsApp/Signal. Is that more secure though? Would a user rather give your random app their phone number than email address? Yes! Even insecure SMS is more secure than email. You know why? Because everybody and their mother is logging and inspecting email, I see people's reset codes and links all the time to every…
> such b.s > I think you skipped over parts of my post > "I refuse to change" is what you are saying > you can think about this longer than a minute > if you read my comment before replying Why are you so hostile? Why use an online forum at all if you will attack anyone engaging with you? You do have some good points there, but is this really the only way you are capable of expressing them?
"Such b.s." refers to what you said, the rest of what you quoted is hostile but not to you as a person but a criticism of your thinking process and an expression of frustration when you take the time to replh but ignore the plain points I made in my comment and make generalized conclusions like how email is the only way without addressing any of the points in my comment that disagreed with what you are saying. I harbor no hostility towards you but I must criticize your argument and thinking process which might require directness and blutness which in a technical site like HN I would expect to be acceptable.
Re: Why don’t we do email verification in reverse?
#316> Plaintext alternatives are the solution, but support is spotty. Very few people use plaintext email clients. According to campaign monitor [1] 67% of users are using graphical email clients. > Takeaway: Inbox delivery can be fickle, unreliable, or outright impossible. The proposed solution to use `mailto:` is also fickle. Users may not have their email client setup or the right client configured in the browser. Als…
> According to campaign monitor [1] 67% of users are using graphical email clients. That same site also says: "Create a plain text version of your email."
Re: Why don’t we do email verification in reverse?
#317Earlier quoted context omitted.
When opening for the first time, Gmail asks to be registered as the mailto handler, but I guess people just hit "no" not knowing what's that about. And there's probably a lot of web-based clients that didn't care to implement this, so yeah, if you want to use mailto links, you better have a big and patient customer support team at hand
Even if all web clients were perfect, and all users understood what a mailto handler is perfectly, wouldn't it still break if people have multiple email addresses? If you have a gmail and a mail from one of Microsoft's mail providers, you can only have one of those webmail pages as your default mailto handler, right?
Re: Why don’t we do email verification in reverse?
#318A general rule of thumb I've built up over the years: resist the temptation to innovate around login! Look at the most commonly used flows that are not obviously terrible and try to implement as close a match to them as possible. When I've tried to innovate around login in the past I've found that any clever ideas I come up with inevitably run into road blocks pretty quickly. Here's one example: why have a separate l…
Been using this passwordless login recipe by supertokens for my recent projects: https://supertokens.com/docs/passwordless/introduction
Re-inventing the wheel calls for a lot more than usually anticipated. Best to keep it simple - and if you do end up innovating might as well open source it or contribute to an already popular OS solution.
Re: Why don’t we do email verification in reverse?
#319Earlier quoted context omitted.
Why should I have to go through all that faff when I have a perfectly good password manager?
Wasn’t suggesting that anyone should - just wanted to suggest a solution to the problem they described.
Re: Why don’t we do email verification in reverse?
#320Earlier quoted context omitted.
Wasn’t suggesting that anyone should - just wanted to suggest a solution to the problem they described.
But they don't have a problem - they just don't use the passwordless sites. If anybody, it's the sites having the problem of missing users.
If nothing else, the idea of having a separate e-mail account/inbox per use case is an interesting one!
Much like those people that use aliases or something of the sort to be able to tell where who sent then a particular email, like if suddenly some shop+my.account@gmail.com started getting random marketing mails.
> If anybody, it's the sites having the problem of missing users.
I mean, isn't that just the consequence of websites optimizing for whatever seems to work for them and forgetting about the minority of users? It might be missed profit, sure, but that depends on just what portion of the users view this as a dealbreaker.
Maybe there could be an app like Google Authenticator that would offer login to multiple websites through one's phone? We already have that in Latvia somewhat, for banking - you enter your user details in the web form and get a prompt on your phone for your PIN to log in with in the web app: https://www.smart-id.com/