The Changelog: Software Development, Open Source

Over the top auth strategies (Friends)

17 snips
Jan 31, 2025
Dan Moore from FusionAuth, an expert in authentication strategies, dives into the world of secure user access. He breaks down modern authentication methods like magic links, OTPs, and passkeys. The discussion highlights the balance between security and user experience, exploring challenges with third-party logins and password managers. Dan shares insights on multi-factor authentication and the importance of evolving strategies for different user demographics. His practical tips and anecdotes make the complex landscape of authentication both relatable and informative.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Offer various auth methods

  • Offer username/password authentication as a baseline option.
  • Include other friction-reducing auth methods like magic links or social logins to increase accessibility.
INSIGHT

Rethinking Forgot Password Flows

  • The "forgot password" flow is often the default user experience for infrequently visited websites.
  • Building auth around this flow, like with magic links, eliminates password storage needs.
ANECDOTE

Changelog's Magic Link Experience

  • Jerod Santo implemented magic links in 2016 to improve security and simplify login for infrequent users of changelog.com.
  • However, delayed emails caused significant user experience issues.
Get the Snipd Podcast app to discover more snips from this episode
Get the app