You are reading a single comment by @Velocio and its replies. Click here to read the full conversation.
  • should emails auto-sign-in when you click those links? We could make that happen. And it would side-step Persona and you'll just be in.

    Wouldn't that punch a big hole in the alleged security benefit which was supposed to be the big selling point of the annoying Persona method?

  • The benefits we argued were:

    1. Save time in development (launch Microcosm sooner)
    2. Be mobile app and API friendly (an integrated HTML form is not)
    3. Don't trust unknown third parties (which may be the application itself, it should never have access to your password, so the app must never have an integrated sign-in form)
    4. Trust a single third party that has a track record of privacy and security

    None of that is weakened by auto sign-in on email links.

    And we already have the very strong notion that "email is your auth method"... if someone has access to your email, then by virtue of that they have access to any account on any service that would send a password reminder to your email.

    So the big assumption behind email as an auth method is: You protect your email.

    Given that... if we send an email to you alone, and it's personalised and it's only for you... then why not make the link in the email sign-in automatically.

    If you're not protecting your email, the whole game is up anyway.

About

Avatar for Velocio @Velocio started