@Yura: Dismissing LunarDraco as being 'overly dramatic' when he raises
an extremely important issue shows you're so blinded by how good you
believe your concept to be that you are ignoring the very opinions you
have canvassed from the community.

I am a web developer, host and - despite my best attempts to persuade
people otherwise - systems support provider and it is scary how many
people refuse to heed warnings of phishing attempts via email or have
heeded them so much that they are scared to open an email unless they
are 150% sure that it's safe and they certainly are not happy to click
on links within them.

So to introduce an alternative way to login where you rely on
receiving a link via email which must be clicked on goes back on the
advice that Banks, Ebay, PayPal, Twitter, Facebook etc. now offer
increasing the chance that people will begin to fall for phishing
attempts on other websites.

If you want people to register and login to your site it is for two
reasons, one to provide you with valid contact details of your user
base that you can then monetize in someway (and valid email is a start
- but you really want a name and idea of location too) and two to
provide your users with a fast but secure way of gaining access to
your site on return visits.

Services such as OpenID, Sign in with Twitter and Facebook Connect
have decreased the number of usernames and passwords we need to
remember whilst reducing the login process to a single click in most
cases.

Your concept requires the entry of an email address, a login to your
webmail or opening of your email client, a download of the emails,
find the one needed (if it has arrived or not been lost in the SPAM
folder), open it up, then click on the link.  And there is also the
possibility of a wait until I get back home as I do not have access to
webmail or have never remembered my POP3/IMAP password as I always
download email into an email client setup by a family member who knows
more about computers than me.

My verdict, you ARE trying to reinvent the wheel and your concept is
not "ensuring that it is as round as it gets".  In fact by introducing
another way to login you are actually muddying the waters even further
than they already are as the sooner the internet universally adopts
one open login process the better as there will then be no confusion
when everyone has one roaming account that they use across the
internet.

Is this a reason to not try and find a better way to login? No,
otherwise innovation fails.  But when you do come up with an idea and
ask for opinions and all those opinions say your concept is not an
improvement, maybe you need to go back to the drawing board.

Check out the new CakePHP Questions site http://cakeqs.org and help others with 
their CakePHP related questions.

You received this message because you are subscribed to the Google Groups 
"CakePHP" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to
[email protected] For more options, visit this group at 
http://groups.google.com/group/cake-php?hl=en

Reply via email to