409
you are viewing a single comment's thread
view the rest of the comments
[-] turmacar@lemmy.world 23 points 1 week ago

I agree the passkey user experience needs work, but man do I enjoy it over the haphazard 'passwordless' website login that just sends you an email.

I get it, they're just skipping an attack vector and basically relying only on '2FA'. But now I have to go to a different app/tab, copy a code, and return to the site instead of letting the password manager fill stuff in for me. Some, like kickstarter, let you still have a 2FA code enabled so you have to grab your code from whichever authenticator and go to your email. Really nice login experience out of nowhere one day. \s

[-] Joelk111@lemmy.world 2 points 6 days ago

The best implementation of this I've seen has to be Ghost, an open source self-hostable newsletter/patreon thing. They detect what email provider you have and when you enter your email, will display a link to open your inbox. It's super neat, and I haven't seen it anywhere else, and I'm also not sure how they do it. For something self-hostable, I'll definitely take one less attack vector.

[-] Scrollone@feddit.it 3 points 6 days ago

Doesn't help if you're not using a huge provider such as Gmail or Hotmail

[-] Joelk111@lemmy.world 1 points 6 days ago

It worked with ProtonMail

[-] Natanael@infosec.pub 3 points 6 days ago

A DNS lookup on a domain says who runs the email server for email users on that domain (that's how email senders figures out how to send you messages), and if that host is a known one then you can just pull the link to show. If you're self hosting email then a few solutions can be recognized and login shown by guessing that the email software's default URL pattern is used.

[-] Joelk111@lemmy.world 1 points 6 days ago

I figured it was something like that, thanks for the explanation!

this post was submitted on 26 Sep 2026
409 points (95.1% liked)

Technology

88491 readers
4510 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS