Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

magic link. That's what medium does for email logins, and slack offers the option as well. it's easily one of the safest methods


Though slack magic links always stay valid... Leaving a nice plain text password for all MTAs that forward my mail.


Ah.. Yes, but that will leave anyone that has somehow gotten access to my mail to suddenly have access to all my accounts then, wouldn't it?


They already do if they have password reset over email. That's why you need 2FA.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: