问 HN:魔法链接身份验证使用 HTML 探查吗?

1作者: trinsic24 个月前
许多网站开始更频繁地使用“魔法链接”身份验证,我想知道这是否也是为了从账户持有人那里获取更多信息的趋势。<p>我不喜欢这种身份验证过程,因为它迫使我每次都必须使用电子邮件系统进行身份验证,这增加了登录所需的时间。 至少在 Claude.ai 上,身份验证过程在您收到电子邮件后,还为您提供了一个使用代码登录的选项。 问题是,电子邮件不包含代码。 您必须点击一个链接,该链接会打开一个网页以获取代码,并且似乎它想在该点执行 HTML 扫描操作。 我觉得在试图登录我付费使用的服务时这样做侵犯了隐私。 我想知道我是否错了,或者是否有人注意到这一点,或者发现了这个过程的差异。 如果这种情况正在发生,可以采取什么措施。 我也想知道越来越多的公司转向这种身份验证方法的真正原因是什么。
查看原文
Many sites are starting to use magic link auth more often and I am wondering if its a trend to also glean more information from the account holder.<p>I dont like this auth process because it forces me to have to use the email system to authenticate every time which adds to the amount of time it takes to log-in. With Claude.ai, the auth process at least gives you an option to use a code to sign in with after you get the email. The problem is, the email doesn&#x27;t contain the code. You have to click on a link which opens a web page to gain the code and it appears at that point it wants to do an HTML canvassing operation. I feel like that is a violation of privacy to do this at the point of trying to log into a service I pay for. I&#x27;m wondering if I am off base or if anyone notices this, or finds a difference in the process. and if its happening, what can be done about it. Also I wonder what the real reason is why more and more companies are moving toward this authentication method.