April 17, 2022, 7:13 p.m. | /u/quentinlintz

cybersecurity www.reddit.com

I’m curious why this isn’t more widespread among web or mobile products. We use our email when we forget our password, anyway. Trusting multiple businesses with your password is gambling depending on their level of security.

Wouldn’t the easiest and most secure way to authenticate users be a magic link or OAuth? (OAuth is still bound to a different company with your password, though).

Are there any shortcomings to the magic link approach?

cybersecurity link login magic

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Audit and Compliance Technical Analyst

@ Accenture Federal Services | Washington, DC

ICS Cyber Threat Intelligence Analyst

@ STEMBoard | Arlington, Virginia, United States

Cyber Operations Analyst

@ Peraton | Arlington, VA, United States

Cybersecurity – Information System Security Officer (ISSO)

@ Boeing | USA - Annapolis Junction, MD

Network Security Engineer I - Weekday Afternoons

@ Deepwatch | Remote