Magic links are passwordless auth methods, that generate unique access links. These are usually valid for a short period of time and normally sent to the email you provide in the login step.
Personally, I'm not a huge fan, and I prefer to login with social accounts, as it's way easier than opening an email each time.
What is your experience with these? Do you use them?
Discussion (23)
And here is a problem. Who you trust more? Your email provider or social company? I would not trust for example Facebook in way to use them to log-in into any website. Still, password and 2FA is way better.
I think using a provider that already has hardened security is still a nice way to login. Honestly, they dont gain much about you other than the fact you use the service X. Their wide spread trackers all around the web does most of the work.
I wish more people cared tho.
Good point on security 🔐😉
Recently we switched away from social accounts (as Google started asking too many questions regarding who are our users and what do they use our app for etc.), we generate a unique login link and send it to user's email address. They can login by clicking the link.
And yes, users love it, remembering/resetting password is a mess, especially when dealing with non technical users. Users still have option for using password, but they often use signin with email.
Hi, do you have any stats to share ? What % of your users are using it ? What's your customer segments in term of age ? What industry ? And no, I'm not the police :D
That's exactly what the post's about. Can you elaborate a bit on whether or not your users like it better this way? 👀
Users like it, specially when they are not very tech savvy.
Great if it works for you and your clients 😉👍
I'm setting up a site right now that will use magic links, the reasoning is a low barrier to entry. My site has an inviting service where users can invite other users, I wanted an invited user to just click an invite link and immediately have access to the site. That sort of thinking just carried over to the whole app and I just got rid of passwords in general.
There is still a remember me option when generating the email token.
I'm enjoying reading the answers here. Considering the possible use of magic links as a Forem feature (in addition to other forms of auth) with some reservations about how to best approach ideas like this from UX and security perspectives.
I spend a lot of time researching this subject and created my own implementation that is using Databunker secure session store:
github.com/securitybunker/databunk...
My implementation of passwordless login with magic link
You can use my example and adjust it for your needs. It is a stand-alone solution. You do not need to pay for any 3rd party service. Here is a link:
github.com/securitybunker/databunk...
To be honest I hate them. I have seen them more on training course providers recently and the issue I have is these are allocated to my work email address which I don’t have access to our of work. This is a huge pain as it means I can’t actually do any of the courses in my own time so it is actually a restriction in my view.
I don't hate them nor love them. I think I have used them once or twice. 🤔 If anything, I typically use social accounts to log into certain sites.
Same here, although I agree with @idarek 's point 😉
Same, but who uses Facebook anyway? 😂 (I know some still do, I just don't want that garbage in my life. Whoops, I said it)
Yeah, probably one of the best decisions I made like 5 years ago 😉
Hahahah, same. Don't wanna get Zuck'd! 🤣
Hahahah, good one 😀😀
I'd say I don't like them, because logging in with a unique id+password is 100% effortless with a password manager, whereas magic links require opening my email which is annoying because it takes time, it's guilt-inducing when there are emails I should be responding to, and it's a context switch because all these other parts of my life appears and suddenly I'm off doing 4 other things and I never did get around to using your service.
Email-notifications for unexpected logins are a fine way to include the email factor without being too intrusive IMO.
Does passwordless auth solve any fundamental security issues?
They're okay, until you want to log in to a site on your work computer and the link is sent to a personal email which is on another device.
I have used them on different sites but not implemented them on my own, TBH I didn't know they were called magic links till now. 👍
Also, magic.link is a great and easy to set up solution if you ever come across the need to use them in your own projects 😉
Really it was very useful content to basic learners and i hope your posts like more this ....Thanks for share with us.. ghdsports.fun/