Discussion
Loading...

Discussion

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Darius Kazemi
Darius Kazemi
@darius@friend.camp  ·  activity timestamp 3 months ago

Websites that let me log in ONLY via email recovery feel like they are personally punishing me as a password manager user... like, come on, I have an awesome, one click, client side way to recall a long unique password for your website but sure, allow me to personally increase your email service bills I guess

In return I get One More Email To Deal With. Thanks pal

  • Copy link
  • Flag this post
  • Block
colombene
colombene
@colombene@social.coop replied  ·  activity timestamp 3 months ago

@darius yes, and often takes more than 20 mins to get the link. I dropped off services for this. Not to be a convenience addict, but this seems such an unnecessary flow obstacle for anything you expect to check more than once a year.

  • Copy link
  • Flag this comment
  • Block
Kyle Davis
Kyle Davis
@linux_mclinuxface@fosstodon.org replied  ·  activity timestamp 3 months ago

@darius there are so many reasons why (IMHO) passwordless login is better for sites and users.

I kinda get the password manager thing but password managers users can be a small % of total users (depending on the demographic). But login is a giant frustration point for a high % of people and that’s even before you touch the functionality of the site.

Otherwise, it’s reasonable to be skeptical of the safety of your credentials. Passwordless avoids that entire category of safety.

  • Copy link
  • Flag this comment
  • Block
Darius Kazemi
Darius Kazemi
@darius@friend.camp replied  ·  activity timestamp 3 months ago

@linux_mclinuxface someone linked me to this article

https://www.404media.co/we-dont-want-your-password-3/

And like. I get it. It is probably better for most users. It's just annoying that I have meticulously optimized one part of my internet life (passwords) and then some sites simply say no and force me into the least optimized part of my internet life (my email, which is a garbage fire of thousands of unread messages and generalized anxiety).

Now that I think of it, my real complaint here might be "email sucks"

404 Media

We Don’t Want Your Password

Some people don't love our magic link logins. But the best way for us to protect your password is to never ask for it.
  • Copy link
  • Flag this comment
  • Block
Kyle Davis
Kyle Davis
@linux_mclinuxface@fosstodon.org replied  ·  activity timestamp 3 months ago

@darius I get it. As far as email being non-optimized, nothing is stopping you from creating a super optimized, login only email account.

  • Copy link
  • Flag this comment
  • Block
haui
haui
@haui@mastodon.giftedmc.com replied  ·  activity timestamp 3 months ago

@darius
AND you become hugely easier to hack and to trace since the email is not encrypted most likely.

  • Copy link
  • Flag this comment
  • Block
Marcus Rohrmoser 🌻
Marcus Rohrmoser 🌻
@mro@digitalcourage.social replied  ·  activity timestamp 3 months ago

Hi @darius,
what other ways do you think of? (https://Seppo.mro.name wants a #ftp delete of the credential file)

  • Copy link
  • Flag this comment
  • Block
Shannon Kay
Shannon Kay
@shannonkay@bookstodon.com replied  ·  activity timestamp 3 months ago

@darius I save the email I used for the website in the password manager, and it does help a bit.

  • Copy link
  • Flag this comment
  • Block
jade
jade
@jadedarko@hachyderm.io replied  ·  activity timestamp 3 months ago

@darius 404 media made a good argument for why they do this - they don't want the complication of storing passwords

it works for them because they are a publication, though - they operate as a mailing list

https://www.404media.co/we-dont-want-your-password-3/

404 Media

We Don’t Want Your Password

Some people don't love our magic link logins. But the best way for us to protect your password is to never ask for it.
  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct