1 day ago · Tech · hide · 0 comments

Cross-posted from the new Kinopio blog From all the confusing and annoying ways to sign in to software we wade through everyday, developers must fear storing/encrypting/hashing passwords. I get it, no one wants to be responsible for screwing up critical security, so authentication has become one of those “no one ever got fired for buying IBM” type of problem that considers the user last. So why has Kinopio only had password-based login since it launched in 2018? Because all the other options are still worse. Let’s go through them: Password-Less Auth With an Emailed Token You go to sign in and type in your email address, then you need to switch to your email app to click the ‘magic link’ to sign in. Using email to authenticate is much less intimidating to build because you don’t have to store or encrypt passwords. But as a user, the result is pain: If you’re lucky the email is ready in your inbox, but usually you’ll be waiting a minute or two for it to show up. (Assuming it doesn’t get…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.