• undefined@lemmy.hogru.ch
    link
    fedilink
    English
    arrow-up
    81
    ·
    8 days ago

    “Magic email” login is the most stupid method to me. Yeah, just make it impossible to log in with my password manager. The average person probably has the weakest password for their email anyway so if a hacker has access to their account you just made it 100% easier for them to log in.

    • JensSpahnpasta@feddit.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      8 days ago

      It’s one of those dark patterns that prevents account sharing. So if you use a magic email login, nobody can share their account with their family & friends and everybody has to pay. Profit!

    • Zorcron@lemmy.zip
      link
      fedilink
      English
      arrow-up
      9
      ·
      8 days ago

      I mean if your email is compromised, most of your accounts can have their passwords reset, no? So it’s basically the same as resetting your password every time you log in. Dumb, I agree, but surely not worse from a security standpoint, right?

      • Owl@mander.xyz
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        8 days ago

        resetting your password every time you log in

        Boomers do that

    • Pyro@pawb.social
      link
      fedilink
      English
      arrow-up
      8
      ·
      8 days ago

      Fully agree, it’s almost security theater.

      They need to offer a way for use with a password manager, maybe a slightly hidden option or detecting a really long password to stop all the extra bits.

      I forgot what the service was but it will have my user and pass, prompt the email verify, and then it will ask for the token generated in an Auth app.

      At a certain point the proper user probably can’t get in

    • Fiery@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      6
      ·
      8 days ago

      To be fair basically all services allow resetting passwords via email so even without the magic email link they’d be fucked anyways if their email got hacked.