Passwordless Login

Caption.me is doing away with passwords. Why?

  • They’re a hassle to remember
  • They’re a security issue (especially if you share the same password across multiple sites)
  • They make the sign-up process more long-winded

Instead, what we’ll do is email you a sign-in link, whether you’re a new or returning captioneer:

image

Email:

image

As before, the site will keep you logged in, so it’ll be rare you have to use this feature.

This is quite a major change on the site, so please let me know if you see any new issues. Thanks!

2 Likes

It’s a good idea.

This is unlikely to happen but if someone hacked into your email account, if after they’ve gained access there was an login link email they’ll be able to get into your caption.me account as well. It would depend on how worthwhile a caption.me profile might be to them .

There’s nothing of overly value on our caption.me accounts that might appeal to a hacker unless they wanted to cause havoc and fuck up an account for shits and giggles. If this were to happen, I’m guessing as administrator Chris you’d have to intervene?

If you couldn’t get access to caption.me as your only port of call has been hijacked, the only problem is then being able to give you a heads up Chris. If I were put in this situation I’d simply set up a new account so I’d be able to contact you and let you know an impostor is using the account.

Naturally being able to control someone’s caption.me account also means they can action captions, comments and votes which considering the discussions that have been previously held in the past few months on here it might lead to further hoo-ha.

I’d find it funny if a hacker did logon to someone’s profile and after trying to cause mischief by submitting captions, they actually get hooked to caption.me and want to become a regular member!

1 Like

The links are single-use, and will also expire after a day or so - so hopefully this won’t be a problem.

1 Like

Back in the day when viruses were a real problem and the internet kept breaking I got into the habit of regularly clearing my temporary files, and it’s something I still do today.

The thing is, when you dump your cookies you get logged out. Under the old password system this was no issue, as my browser retained login info so it was just 2 clicks and back on deck. By comparison the email system is pretty laborious.

Obviously this is only an issue if you get logged out. But deleting cookies does this, and while browsers allow you to delete cookies from individual sites, most don’t allow you to make specific sites exempt from cookie deletion.

I know you can get third party cookie cleaners that will probably do the trick, but I was wondering if there was any other work around? As it stands I’ll probably just stop deleting my cookies nearly as often so I don’t have to keep logging on.

Hmm, that’s an interesting challenge.

I could create a personalised link that contains the data normally stored in your caption.me cookies. Every time you click the link, it would ensure you were signed in.

The downside is that anyone who gets hold of the link would own your caption.me account. But if you think that’s a reasonable trade-off vs the inconvenience of email login, I can implement it as an optional feature of the site. Let me know.

1 Like

It’s no major drama, Chris. I can just stop deleting cookies as often. It’s weird that browsers don’t let you make specific sites exempt from cookie deletion. That would be an easy fix.

2 Likes

A possible minor inconvenience could be when I, just occasionally, use my phone instead of my desktop to access Caption.me - e.g. when I am out and about at noon. I don’t use my phone for e-mail, ever. If I were to enable it for the sake of an OTP from Caption.me, I would get a flood of mail to the phone which I really do not want. But it’s not a huge problem - I would just refrain from posting or voting when not at home.

1 Like

For that purpose I could make a page where you can scan a QR code in order to log in on your phone. I’ll add that to the todo list

Coming back here after the discussion in the topic I’m not staying logged in - I see that the ToDo list entry “Tech: login improvements” refers to scanning a QR code from an e-mail, which wouldn’t address the problem of not having (or choosing not to have) e-mail access on one’s phone.

If you had email access on a computer, say, you would open the email on your computer screen and then scan the QR code from that screen using your phone’s camera. Then the QR code would log your phone into caption.me

Yes - but if I was at my computer, I would be accessing caption.me via my computer browser. The times I want to access it via my phone are when I am out and about. I guess there is no way around this at all, in the absence of a password of some sort.

Once your phone is logged in, it should stay logged in forever. So you’d only need to scan the QR code once, and then you could use caption.me when out and about on your phone

But there’s a hole in my bucket, dear Liza, dear Liza… :upside_down_face:
Seriously, you concentrate on getting the people who depend on their phones for caption.me to be able to log in more easily; I am in a minority of one, and certainly don’t expect special adjustments to be made just for me.

Hi @Molly_R. I’ve improved the sign-in process so you can either click a link or enter a six-digit code from the email.

This should make it possible to sign in on devices that don’t have email access.

1 Like

That works perfectly, Chris - thank you so much! Just last Sunday I was out at lunchtime, and wanted to check the noon photo but was logged out on my phone; now, it will just be a matter of checking before I go out, making a note of the 6-digit code, and entering it on the phone when I am ready to log in. How long is the code valid for?

Ah, it’s not really intended for logging in like that - the code only lasts a matter of minutes. But the login should last forever, so once you’ve logged your phone in once, it should stay logged in. Let me know if this is not the case for you.

1 Like

I had a system update a few days ago, after which I was no longer logged in; but I guess it “sticks” until there is a re-boot. I’ll just remember to re-log in while at home after the next re-boot, and then everything should be just fine. Many thanks!

2 Likes