Why we went passwordless on our new product
1–10 of 76 posts
Re: Why we went passwordless on our new product
#2What can happen is better federated SSO using OAuth2 like Apple, Google, FB, Github, and/or similar for web applications to defer or eliminate yet another mandatory password.
Re: Why we went passwordless on our new product
#3You can't "solve" passwords because authentication requires something you have or something you know. Not everyone has email, magic links by email are insecure, and it defeats the ubiquity of password managers and keychains. There's no eliminating private keys or passwords anytime soon because it's a utopian aspiration wishing away first principles. What can happen is better federated SSO using OAuth2 like Apple, Goo…
Then you get locked out of like 9 things at once when {you ragequit github for political reasons and forget to migrate everything, google kills yet another thing, google locks your account for funsies, apple locks your account until your macbook pro refund is processed correctly,....}
Re: Why we went passwordless on our new product
#4Re: Why we went passwordless on our new product
#5You can't "solve" passwords because authentication requires something you have or something you know. Not everyone has email, magic links by email are insecure, and it defeats the ubiquity of password managers and keychains. There's no eliminating private keys or passwords anytime soon because it's a utopian aspiration wishing away first principles. What can happen is better federated SSO using OAuth2 like Apple, Goo…
I think passwordless-only is a bad call for the consumer market. Notion ran passwordless for years but we dealt with constant issues of users losing access to their email and having no (easy for them) way to prove ownership of the related Notion account. We switched to normal password accounts.
Re: Why we went passwordless on our new product
#6You can't "solve" passwords because authentication requires something you have or something you know. Not everyone has email, magic links by email are insecure, and it defeats the ubiquity of password managers and keychains. There's no eliminating private keys or passwords anytime soon because it's a utopian aspiration wishing away first principles. What can happen is better federated SSO using OAuth2 like Apple, Goo…
>What can happen is better federated SSO using OAuth2 like Apple, Google, FB, Github, and/or similar for web applications to defer or eliminate yet another mandatory password. Then you get locked out of like 9 things at once when {you ragequit github for political reasons and forget to migrate everything , google kills yet another thing, google locks your account for funsies, apple locks your account until your macbo…
Re: Why we went passwordless on our new product
#7You can't "solve" passwords because authentication requires something you have or something you know. Not everyone has email, magic links by email are insecure, and it defeats the ubiquity of password managers and keychains. There's no eliminating private keys or passwords anytime soon because it's a utopian aspiration wishing away first principles. What can happen is better federated SSO using OAuth2 like Apple, Goo…
It bears the same risk of the unique access being lost as having unique access to your finger for finger print scanning, minus the risk of physical injury on compromise.
Re: Why we went passwordless on our new product
#8You can't assume the email will be delivered so quickly.
Who wants to get locked out of their account because the email has not arrived?
Login links can be a convenience feature but they must not be the only mechanism for login.
Re: Why we went passwordless on our new product
#9Re: Why we went passwordless on our new product
#10Offer a password option, people! Back it up with a magic link if you must but offer a password!
Especially if your magic links go to spam.