| ▲ | kyle-rb a day ago | |||||||||||||
> Emails are super easy to hack Source? And if somebody hacks my Gmail account, won't they be able to access my Google-synced passkeys? Magic link auth isn't any less secure than any site that has a password-reset flow. | ||||||||||||||
| ▲ | nunez a day ago | parent [-] | |||||||||||||
A family member installed an app into their Android phone from the Play Store. It was innocent enough until it asked for a truckload of permissions, like being able to change the launcher, which they ofc tapped "Allow" to since permission request fatigue is real and still a bit of an unsolved problem. So the app delivered on its promise and changed their phone's launcher. It had a fake Gmail widget that showed them their mail but, of course, wasn't actually tied to the actual Gmail app and was an easy way of getting a refresh token for their account. Bingo bango bongo: their email was now at risk. They changed their password after I told them to right away upon them asking me to look at their phone because "it was slow." > Magic link auth isn't any less secure than any site that has a password-reset flow. Which is exactly the problem. Cloning someone's SIM/eSIM and immediately performing password resets is a well-known security issue. | ||||||||||||||
| ||||||||||||||