Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Slack and their magic links are probably the most common exposure your users will have to this model.

I can't speak on behalf of them, but I absolutely loathe sites/services that require logging in through email. It's fine if it's just one log-in option, but if a site makes it the only option, it's very likely I will not be using that site. From what I've heard from peers (both tech-savvy people using password managers and less-tech-savvy people confused by the seemingly-random tie-in to their email login), I've never heard anyone actually say they like the flow. In my experience, they very strongly dislike it.

If you're doing it to "increase security", I recommend taking an approach closer to Steam: if someone logs in from a new or unrecognized device, send a code to their email and require them to confirm. It's still intrusive, but way less so since you have to deal with your email way less often.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: