Logging in Verification Magic Links, 2FA, SMS Codes

  Рет қаралды 2,218

Syntax

Syntax

Күн бұрын

Пікірлер: 11
@JoelBourbonnais
@JoelBourbonnais Күн бұрын
Hey guys! Great episode! The magic session as you called it to activate devices is usually the well documentend OAuth flow called Device Authorization Flow. Usually when the flow is different, it is because you don’t want the device to be logged in « as you » but rather be added to your account as « its own thing ».
@AnthonyBullard
@AnthonyBullard 3 күн бұрын
Passkeys are the future. The thing with magic links that most devs don’t appreciate is that you reduce your attack surface for individuals a lot. Basically MFA as default
@christophorus991
@christophorus991 Күн бұрын
I had high hopes for them, but so far I'm not convinced. It's been a messy user experience trying to get them setup and working reliably with 1Password
@Pygon2
@Pygon2 15 сағат бұрын
Regarding magic links, I think it heavily depends on the type of application. I would never want my banking access to be protected by just my email address. That seems insane. I get the allure of it, because then developers (and companies) can simply say "not my problem" and move on, but there are plenty of SSO options that can handle this for you. In my personal opinion, this sounds a bit like trying to say, "This is more secure because now you have one key that unlocks your house, your cars, your safe with all your valuables, and everything else you own." It seems to ignore that most people will typically leave this same important key lying around on every one of the devices they use, typically protect access to it with only a 4-6 digit pin or a simple password, and is often left completely unsecured in environments they feel "safe" in.
@AnthonyBullard
@AnthonyBullard 15 сағат бұрын
@@Pygon2 if someone has your phone, you are screwed. The same with your email. But again, the future and real long term answer is passkeys. I plan to move all of my apps to 100% passkeys in the next year
@maxz999
@maxz999 3 күн бұрын
Magic links suck. Especially when you have a device where you aren’t logged in to your email.
@clarkio
@clarkio 2 күн бұрын
Great episode! I generally turn away when a site ONLY offers a google oauth or requests a phone number (like Wes mentions at the end). Often I don't want to give up that info anymore than I already have. Also I never thought of "roll your own" auth in this manner so that was helpful. I've always thought of that as building your own username/pass login flow (plus register, refresh tokens, etc.) and managing that data in an app which is something I've always stayed away from and told others to do the same.
@anythingfx8950
@anythingfx8950 3 күн бұрын
First 😂 haven't watched yet but I am sure it is a bomb. Thanks GOATs
7 Cybersecurity Tips NOBODY Tells You (but are EASY to do)
13:49
All Things Secured
Рет қаралды 409 М.
HTMX is Pro-JavaScript @JSNation - Interview w/ Carson Gross
12:47
Стойкость Фёдора поразила всех!
00:58
МИНУС БАЛЛ
Рет қаралды 5 МЛН
An Unknown Ending💪
00:49
ISSEI / いっせい
Рет қаралды 57 МЛН
You Need These 30 Apps  - PART 2
56:29
Syntax
Рет қаралды 8 М.
Microservices are Technical Debt
31:59
NeetCodeIO
Рет қаралды 403 М.
Hackers Bypass Google Two-Factor Authentication (2FA) SMS
12:47
John Hammond
Рет қаралды 1 МЛН
12 INSANE Use Cases for NEW ChatGPT Advanced Voice! (Amazing Results)
29:22
Rethinking Authentication by Frank Denis
42:05
TigerBeetle
Рет қаралды 2,4 М.
Upgrade Your AI Using Web Search - The Ollama Course
8:12
Matt Williams
Рет қаралды 13 М.
iOS 18 is AMAZING! - Try these 10 things first!
17:18
Proper Honest Tech
Рет қаралды 3,9 МЛН
What’s the Best Two-Factor App?
9:23
Ask Leo!
Рет қаралды 10 М.
Syntax Assistant Desktop App
28:34
Syntax
Рет қаралды 3,7 М.
Run ALL Your AI Locally in Minutes (LLMs, RAG, and more)
20:19
Cole Medin
Рет қаралды 115 М.
Стойкость Фёдора поразила всех!
00:58
МИНУС БАЛЛ
Рет қаралды 5 МЛН