Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Good point. My thoughts: - Email is not the only option to deliver tokens. You could also go for SMS, or both - For most registrations such emails are anyway commonplace. Combined with long sessions (where possible), I think the risks of delayed emails are low (compared to guys getting frustrated with the password) - I'm so far happy with Mandrill. But as you say: random b.s. can happen


Random b.s. happens with SMS messages too. I've waited minutes for tokens from my bank's login system on more than one occasion.

Also it's not always the case that a user has access to email when he's trying to log in to your app.


Yes, stuff happens. But as said: Most services use long-lived sessions. It's a choice: Trouble people with either insecure passwords and password resets, or take the risk that sometimes when a session was closed people might in rare cases not receive their tokens. Looking at my daily browsing I would be more than happy to get rid of most of the passwords.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: