TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Are auto login tokens in transactional emails bad practice?

4 点作者 sspross超过 9 年前
Hi HN, what do you think about auto login tokens in transactional emails? If the user has multiple devices (e.g. desktop at work, ipad at home) it&#x27;s just very convenient. We also offer login with social accounts (e.g. facebook, google) but most of our users still register by email.<p>Whats your opinion?

1 comment

Isammoc超过 9 年前
I&#x27;ve seen a website without password. To login: you have to fill you email adress, they send you an email with a one time auto login token.<p>It was great!<p>But (because, there is a &quot;but&quot;) it was (I repeat) a <i>one time</i> auto login token.<p>If there was a for ever auto login token, this mail may be lost, duplicate, or worse, compromised.<p>The <i>one time</i> auto login is &quot;secured&quot; in the way you know you will have first access to this mail (mail is mostly unsafe) and the link worked.<p>Advantage : only one password (double authenticated for several providers) for your mail. As would be an oauth connection.<p>In a transactional mail ? Muh... &quot;transactional&quot; mean with an action, but commonly with a paid action, with private informations like a credit card number... I will not feel safe if in the same email I have a confirmation I have paid something (ie: advice about payment information are provided) and a link that allows the mail reader to get those informations.<p>There were my 2 cents.