• TheEighthDoctor@lemmy.zip
    link
    fedilink
    English
    arrow-up
    28
    ·
    21 hours ago

    It’s especially good when you already have an account but accidentally press the Google button and then it creates a duplicate account with the same email and breaks the login for your regular email.

  • Epzillon@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    16 hours ago

    As a web developer I simply have to tell you that this clearly superior web design is the only thing I ever implement. You have to understand the maximized convenience this workflow gives the user and the UX implementation for this makes the login experience flawlessly seamless without any hickups. /s

    Jokes aside. How the fuck did we even get here?

  • Cousin Mose@lemmy.hogru.ch
    link
    fedilink
    English
    arrow-up
    78
    ·
    2 days ago

    “Magic email” login is the most stupid method to me. Yeah, just make it impossible to log in with my password manager. The average person probably has the weakest password for their email anyway so if a hacker has access to their account you just made it 100% easier for them to log in.

    • Fiery@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 day ago

      To be fair basically all services allow resetting passwords via email so even without the magic email link they’d be fucked anyways if their email got hacked.

    • JensSpahnpasta@feddit.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      1 day ago

      It’s one of those dark patterns that prevents account sharing. So if you use a magic email login, nobody can share their account with their family & friends and everybody has to pay. Profit!

    • Zorcron@lemmy.zip
      link
      fedilink
      English
      arrow-up
      9
      ·
      1 day ago

      I mean if your email is compromised, most of your accounts can have their passwords reset, no? So it’s basically the same as resetting your password every time you log in. Dumb, I agree, but surely not worse from a security standpoint, right?

      • Owl@mander.xyz
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        1 day ago

        resetting your password every time you log in

        Boomers do that

    • Pyro@pawb.social
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 day ago

      Fully agree, it’s almost security theater.

      They need to offer a way for use with a password manager, maybe a slightly hidden option or detecting a really long password to stop all the extra bits.

      I forgot what the service was but it will have my user and pass, prompt the email verify, and then it will ask for the token generated in an Auth app.

      At a certain point the proper user probably can’t get in

  • ExLisper@lemmy.curiana.net
    link
    fedilink
    English
    arrow-up
    3
    ·
    20 hours ago

    I wonder if it’s because some usage statistics tell those sites that 99% of users visiting the site are already logged in and the only case someone is not logged in when they don’t have an account yet or if they are just stupid.

  • HollowNaught@lemmy.world
    link
    fedilink
    English
    arrow-up
    23
    ·
    1 day ago

    My biggest annoyance with these processes is when they ask for your user name (loading…) then takes you to a different page to ask for your password (loading…)

    Like, just stick them on the same page, it’s an annoyance for the sake of trying to get us to use auto sign in

    • Jako302@feddit.org
      link
      fedilink
      English
      arrow-up
      12
      ·
      1 day ago

      it’s an annoyance for the sake of trying to get us to use auto sign in

      Not really, that’s more in the realm of incompetence than malice. Its basically the cheapest and fastest way to implement multiple different log in methods within one login page.

      Let’s say you have Google login, Facebook login, SSO (corporate single sign-on), Email/SMS codes and good old password and username. The easiest option would be to just put a different login button for each of these and be done with it. That works as long as your users know what type they should use.

      But once you have a user that doesn’t know what he should use you need a backup login that always works. Thats what the standard login button is used for nowadays. When you put in your username/Email it checks the associated login method for that account and redirects you to the correct login page. That way multiple login methods can be accessed with the same starting page.

      Sure, its mildly annoying for people that use a normal passwords, but considering that the overwhelming majority of people either uses Google sign in or just stays logged in, its a very easy decision to make for the developers.

  • LogicalDrivel@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    15
    ·
    1 day ago


    I got this yesterday after signing back in to my google account. Like fuck off, google, i know you already know my address. Its just for those “ads purposes” they try to sneak in the bottom there.

    • Law Abiding VPN User@feddit.org
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      Oh God…I fucking hate google so much. Every time I have to sign in again it asks me to do that. No, google, fuck off, you don’t need to know who I am to do what you do for me

      I’m just glad my google account is old enough to not have to submit my ID to see age restricted videos on youtube. By the way, if you have a google account that’s over 15 years old DON’T DELETE IT that’s an asset you can use and be sure to make a new profile in your browser to compartmentalize your google activity into just that one profile

  • ChaoticNeutralCzech@feddit.org
    link
    fedilink
    English
    arrow-up
    9
    ·
    1 day ago

    My sister told me she had problems recovering her password. The page said “email address not registered” when she tried that but “email address in use” when she tried to create a new account. She eventually tried “Sign in with Google” (it was a Gmail address), which led to a permission page, making it seem like she was setting up a new connected service to the account. She went through with it and saw her profile page with all her details, history and credits. By the time she navigated to another page, her account had been reset to a new one with nothing but an email address… The service admins did have a backup though and restored the account.

    And I remember a site that would show you your password in account details, and did not even support https… in 2011 up to fucking 2015. Gaining control of all 300,000+ accounts (not hard if the backend’s security was as strong as it seems to have been) would not have been valuable itself (users could not interact, the site was basically a quiz game with a leaderboard akin to freerice.com) but it was for children 6-18, most of whom would reuse passwords. And it was designed by CDI.cz, a major web design agency with high-profile Czech clients including the post office, a top 3 telecom, a major heath insurance provider and the national railway company…

  • RedGreenBlue@lemmy.zip
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 day ago

    After the age check laws take effect; you won’t need to log in. They will know who you are.

    You only have to type the url in your browsers adress bar and you will recieve your obligatory bone sampling kit in your mail box the next day.