A bold but simple login system
notes.xoxco.com
A bold but simple login system
1–10 of 101 posts
Re: A bold but simple login system
#2I don't buy his premise, either; he claims you need to interact with "6 different controls" to log in to Facebook, but (a) you only interact with 4 of them and (b) that's only the first time you log in from that computer. He's trying to solve a problem I have never experienced. I'm curious to see if others have felt overwhelmed by the number of controls on login forms; this is a problem I've never had.
Re: A bold but simple login system
#3Even most incompetent users like my mum save their password into the browser keychain so it ends up bring only a single click anyway.
Things like browserID are solving this far more simply.
Re: A bold but simple login system
#4Non-power users (11 yo kids) maybe don't always have their inbox open/session active.
Best case scenario with one e-mail entry for multiple devices stand in conflict with link only being usable once.
Don't get me wrong, I think passwords are horrible but this post was just made in too much of a hurry.
Interesting topic!
Re: A bold but simple login system
#5Re: A bold but simple login system
#6Re: A bold but simple login system
#7Enterprise users seem to be on Outlook all the time checking their e-mails so this would work if you can't tie your passwords into AD/Exchange.
Maybe have an option to have a token that can be entered or a link clicked.
I get all my e-mails on my phone so if I received a code that I can enter in my phone that can work. I could also click a link in Outlook and be logged on.
Now if someone has my phone which is receiving my e-mails and they enter the e-mail on a website and receive the secure login we got a big problem. I don't know how to get around that.
Interesting discussion, but some flaws. I would think it requires some sort of 2-factor auth to save people whose e-mail addy is compromised.
Re: A bold but simple login system
#8Also, using an email backchannel and one time keys moves the security from an encrypted connection (assuming SSL) to an unencrypted SMTP connection anyone can view...
Back in the good old days of UUCP you might wait a day or two to get mail from across the globe...
Re: A bold but simple login system
#9Re: A bold but simple login system
#10We could suggest that Facebook implement something like this. Seeing a login control containing 950MM names would be rather comical.