Answer the question
In order to leave comments, you need to log in
Have you heard of authorization via email?
When the user does not need passwords, and to enter, you only need to enter your email address and follow the link in the message that you receive.
What disadvantages does this method have over the usual login / password?
And is it possible without fear to enter it into the application?
Answer the question
In order to leave comments, you need to log in
This method is also called "Magic Link". In this way, you can enter the website of the online store mann-ivanov-ferber.ru or medium.com, for example.
The advantage of this solution is that the site user does not need to invent and remember a password. This is very cool because security issues do not lie with you, but with those who provide mail service services.
The downside of this solution is that the user needs to log in via mail. But in reality, for many users, it is less tedious than, for example, entering and remembering a password. Especially if you do not reset the session by timer, but automatically renew it with TTL when the user does something on the site.
A more convenient solution (for users of mobile sites) would be to generate and send a one-time password via SMS. In this case, the user will immediately read the password from the notification without switching to any third-party services.
For me, as a user, this complicates things.
I want to enter the site, and not be distracted by the mail tab. And then, if such a tab is open and the mail came immediately.
Who doesn't use password managers these days?
Between two sites with identical content and functionality, differing only in the login system, I will choose the classic option.
This method is based on the assumption that “everyone uses e-mail. mail."
Just like a one-time password for SMS - from the fact that "everyone uses a mobile phone."
Or “everyone has an account in the social. networks".
These hypotheses are true in most cases, but not 100%. If you want to conveniently cover everyone, it is better to offer a choice of authorization methods.
You are generating a token for the user that replaces the password.
The authorization link is in the user's email.
In fact, you send a "password" to the mail.
The disadvantages are the same.
See for yourself - the login link simplifies registration.
If that's your goal, go for it.
Well, for me personally, this is not very convenient, for example with mobile networks.
I do not need to log into your account on your site, but enter the mail, follow the link, and at this time I can change my mind about my plans for your resource.
Everyone will be just too lazy to go to the post office. The ideal authorization option is one-click login through the social network. The fewer clicks you need to make for an action, the better.
Obviously, you just need to combine. After registration, it is necessary to confirm the email once by following the link, then, if desired, either by following the link or entering the password that is initially generated and also sent to the mail, then you can change it. The link will have a timeout, for example, a month, after it either logs in with a password or the button next to remember the password is sent to the email.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question