WebbedIT, I really appreciate your input, thank you. I'll go discuss it with myself and add your words to the case.
On Mar 16, 11:12 am, WebbedIT <[email protected]> wrote: > @Yura: Dismissing LunarDraco as being 'overly dramatic' when he raises > an extremely important issue shows you're so blinded by how good you > believe your concept to be that you are ignoring the very opinions you > have canvassed from the community. > > I am a web developer, host and - despite my best attempts to persuade > people otherwise - systems support provider and it is scary how many > people refuse to heed warnings of phishing attempts via email or have > heeded them so much that they are scared to open an email unless they > are 150% sure that it's safe and they certainly are not happy to click > on links within them. > > So to introduce an alternative way to login where you rely on > receiving a link via email which must be clicked on goes back on the > advice that Banks, Ebay, PayPal, Twitter, Facebook etc. now offer > increasing the chance that people will begin to fall for phishing > attempts on other websites. > > If you want people to register and login to your site it is for two > reasons, one to provide you with valid contact details of your user > base that you can then monetize in someway (and valid email is a start > - but you really want a name and idea of location too) and two to > provide your users with a fast but secure way of gaining access to > your site on return visits. > > Services such as OpenID, Sign in with Twitter and Facebook Connect > have decreased the number of usernames and passwords we need to > remember whilst reducing the login process to a single click in most > cases. > > Your concept requires the entry of an email address, a login to your > webmail or opening of your email client, a download of the emails, > find the one needed (if it has arrived or not been lost in the SPAM > folder), open it up, then click on the link. And there is also the > possibility of a wait until I get back home as I do not have access to > webmail or have never remembered my POP3/IMAP password as I always > download email into an email client setup by a family member who knows > more about computers than me. > > My verdict, you ARE trying to reinvent the wheel and your concept is > not "ensuring that it is as round as it gets". In fact by introducing > another way to login you are actually muddying the waters even further > than they already are as the sooner the internet universally adopts > one open login process the better as there will then be no confusion > when everyone has one roaming account that they use across the > internet. > > Is this a reason to not try and find a better way to login? No, > otherwise innovation fails. But when you do come up with an idea and > ask for opinions and all those opinions say your concept is not an > improvement, maybe you need to go back to the drawing board. Check out the new CakePHP Questions site http://cakeqs.org and help others with their CakePHP related questions. You received this message because you are subscribed to the Google Groups "CakePHP" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [email protected] For more options, visit this group at http://groups.google.com/group/cake-php?hl=en
