frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Does magic link authentication use HTML canvassing?

2•trinsic2•8h ago
Many sites are starting to use magic link auth more often and I am wondering if its a trend to also glean more information from the account holder.

I dont like this auth process because it forces me to have to use the email system to authenticate every time which adds to the amount of time it takes to log-in. With Claude.ai, the auth process at least gives you an option to use a code to sign in with after you get the email. The problem is, the email doesn't contain the code. You have to click on a link which opens a web page to gain the code and it appears at that point it wants to do an HTML canvassing operation. I feel like that is a violation of privacy to do this at the point of trying to log into a service I pay for. I'm wondering if I am off base or if anyone notices this, or finds a difference in the process. and if its happening, what can be done about it. Also I wonder what the real reason is why more and more companies are moving toward this authentication method.

Comments

Gametroleum•8h ago
I believe this is the reason:

Imagine, you work in bigCorp. You have company email address: my-name@bigCorp.com

bigCorp pays for your access to SaaS service.

You switch jobs, your email is revoked/removed. You can not log in anymore.

If there was no 2FA via email - you still can access service with email+password in case they failed to remove your access to specific service.

If all services use 2FA via email - bigCorp has less access problems.

That is also partly related with SAML/SSO lack of "sign off".

raw_anon_1111•6h ago
No BigCorp would ever use a SaaS product that doesn’t have SSO federation. No IT department wants to keep track of individual logons.
kay_o•2h ago
0) Word you want is fingerprinting ?

1) They can already do this at the login point before the email is send

2) It is more likely, for general users, such that users reuse passwords and get stuffed often

NoahZuniga•2h ago
Consensus in the security space is that passwords are really bad. So many products are migrating away from passwords to magic links/passkeys.

Ask HN: Anyone know of that "levels of AI programming" blog post?

4•tuvix•7h ago•4 comments

Ask HN: Building a solo business is impossible?

53•fnoef•1d ago•75 comments

Ask HN: Does magic link authentication use HTML canvassing?

2•trinsic2•8h ago•4 comments

Ask HN: Who is using OpenClaw?

335•misterchocolat•3d ago•379 comments

Ask HN: ChatAi web-based session notation?

2•xtiansimon•10h ago•0 comments

Tell HN: Fiverr left customer files public and searchable

823•morpheuskafka•4d ago•230 comments

Why don't we just ask AI to write assembler?

6•canterburry•18h ago•11 comments

Tell HN: 48 absurd web projects – one every month

78•absurdwebsite•2d ago•26 comments

Ask HN: How can I support the AI resistance movement financially?

8•roschdal•5h ago•7 comments

Ask HN: How did you get your first users with zero audience?

15•arikusi•2d ago•9 comments

Ask HN: Getting depressed day by day, how to cope?

18•throwaw12•1d ago•18 comments

Do I Stop Learning Coding? DSA?

6•s_u_d_o•1d ago•13 comments

Tell HN: Security Incident at Porter (YC S20)

6•leetrout•1d ago•0 comments

Ask HN: How do you maintain flow when vibe coding?

30•fny•2d ago•29 comments

Aliens.gov Resolves – To a WordPress "Site Not Found" Error

11•ascarola•2d ago•6 comments

Ask HN: How do you search the web programmatically these days?

5•coreyp_1•1d ago•5 comments

Ask HN: How do you find motivation to do stuff?

25•RockstarSprain•3d ago•25 comments

Ask HN: Teaching life skills through games, am I crazy?

2•shivaniShimpi_•1d ago•2 comments

Ask HN: How are you using LLMs in production?

13•Anon84•2d ago•11 comments

Advice for tracking down a listening device?

8•comrade1234•2d ago•5 comments

Durable Object alarm loop: $34k in 8 days, zero users, no platform warning

29•thewillmoss•3d ago•2 comments

Ask HN: Who is your favourite Entrepreneur/Visionary?

13•wasimsk•2d ago•32 comments

Tell HN: Anthropic no longer allows you to fix to specific model version

26•baobabKoodaa•3d ago•2 comments

Ask HN: Is Claude Getting Worse?

9•sahli•3d ago•19 comments

Ask HN: How are you actively keeping your thinking sharp while using LLMs daily?

15•smonk108•2d ago•10 comments

Opus 4.7 is horrible at writing

18•limalabs•1d ago•25 comments

Ask HN: How to highlight talent from untraditional backgrounds?

6•etherus•2d ago•5 comments

GitHub gave webhook secrets away in webhook call

12•time4tea•4d ago•1 comments

Ask HN: As an Australian, is it possible to get a remote US role?

4•apatheticonion•3d ago•8 comments

Ask HN: LeetCode, anyone still doing it?

19•kwar13•4d ago•14 comments