I've been seeing more and more usage of the "magic link" (submit email address, receive tokenized URL in an email, click link to sign in) pattern in web _and_ mobile apps.<p>I, myself, tend to favor it. I'm skeptical of the general public's acceptance, though.<p>For those of you building apps with both options, what numbers are you seeing around its adoption?<p>Thanks!
"submit email address, receive tokenized URL in an email"<p>... is a known-vulnerable antipattern, because email normally exposes that token to third parties.<p><a href="http://www.goironbox.com/why-email-is-not-secure/" rel="nofollow">http://www.goironbox.com/why-email-is-not-secure/</a>