Ability to Set a Password

Currently, to log into sync in both the browser or on Android, you must enter a code received by e-mail. The problem with this is that e-mail is not secure, so the code could be intercepted.

Whilst the majority of account systems allow you to reset your password by e-mail, so may not at first seem anymore secure than the above method, there is one major difference: if an attacker intercepts a password reset e-mail and changes your password, you will know about it the next time you log in and your password doesn’t work. However, by logging in with a code, you have no idea that your account is compromised.

This will be especially bad for people who have controlling partners who like to spy on them and who may also have access to their e-mail on a shared computer. (This isn’t a concern for me, but might be for some).

Also, thanks for the app, it’s really great!

Please authenticate to join the conversation.

Upvoters
Status

Rejected

Board
Custom icon

Structured

Date

About 1 year ago

Author

Ascy

Subscribe to post

Get notified by email when there are changes.