Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is essentially the same system that Netflix and other services use to authenticate devices. Simply include an N character (usually 5) random code that expires in minutes (10-20). They can type in this code on whatever device they want to authenticate.

Include a link in the email in case they are currently on the device they want to authenticate.

This solution is good for long term authentications (registering a device to a service e.g. my Xbox to Netflix), but cumbersome for a service I log into frequently from many unique devices.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: