Lot's of services realized that users would use the reset password form for login.
Emailing a one-time code is worse than passwords
21–30 of 816 posts
Re: Emailing a one-time code is worse than passwords
#22The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…
Re: Emailing a one-time code is worse than passwords
#23Re: Emailing a one-time code is worse than passwords
#24Re: Emailing a one-time code is worse than passwords
#25Re: Emailing a one-time code is worse than passwords
#26I thought this was going to be about Passkeys. Maybe if the FIDO Alliance can stop being obstinant and allow real backups, I'd be all in on them.
(I do agree with you about backups being essential, but my conclusion was "the idea is fundamentally flawed," rather than "it's one tweak away from greatness.")
Re: Emailing a one-time code is worse than passwords
#27I thought this was going to be about Passkeys. Maybe if the FIDO Alliance can stop being obstinant and allow real backups, I'd be all in on them.
Re: Emailing a one-time code is worse than passwords
#28Earlier quoted context omitted.
Even with backups, the attestation issue makes them awful.
I'm not familiar with this issue and a quick search didn't turn up anything obvious. Would you mind elaborating?
It's copied over from FIDO hardware keys where each device type needed to be identifiable so higher tier ones could be required or unsecured development versions could be blocked.
Re: Emailing a one-time code is worse than passwords
#29Very short, badly written article. It can't even describe phishing correctly... At least label your threat model correctly. While the premise is correct -- it's easy to complain but the author also provides zero recommendations on what is a better form of MFA.
Re: Emailing a one-time code is worse than passwords
#30Very short, badly written article. It can't even describe phishing correctly... At least label your threat model correctly. While the premise is correct -- it's easy to complain but the author also provides zero recommendations on what is a better form of MFA.