tags:

views:

113

answers:

5

What is the best approach for creating a password-less login system?

I'm thinking to use some sort of randomly generated 16 character token, for example:

mysite/members/index.php?token=2j0n1qyjgcxyu3oy

I'm developing a quotation system and the idea is that the suppliers don't have to register, instead I create their account for them and all they have to do is click the link in their email in order to submit a quote. This will encourage suppliers to submit a quote, as they'll know they don't need to register or log in.

There isn't much harm that someone could do should they happen to guess the token, but I'd still like to make the system as secure as I can without requiring a password.

+4  A: 

A token would be fine, I would use an MD5 or SHA1 hash for it.

But so you are aware, which it seems you are, this can be sniffed by packet sniffers, especially through email, so just know that. But if that is not an issue, I do not see a problem with using a token for a supplier. If it does get sniffed or abused, simply re-generate a new token for them.

Hope that helps.

Brad F Jacobs
Do you mean the token should be an MD5, or I should compare the token to an MD5 version of the token stored in the database?
GSTAR
The token itself would be an MD5, not "necessary" persay, but that would be my preference.
Brad F Jacobs
Keep in mind that if the cookie is reset, the user will lose all their account info forever.
BlueRaja - Danny Pflughoeft
What cookie? This is more or less just a hash and regenerating a token just updates the database with a new "Access" key. I do not see how that would "lose" their account information forever. I am taking it that the business email is in the database, so if a token is re-generated it is a simple re-email of their new access key.
Brad F Jacobs
Cheers premiso. I'm just trying to understand all this. If we're just comparing the MD5 token with the value in the database, then why not just use the random character generator to generate a random 32/64 character string? Or am I missing something here?
GSTAR
Nope, you can sure do that. A hash, imo, would just be easier, but if you prefer the generate a random 32/64 character string, go for it! This is all preference on how you want to handle it, honestly. Just be consistent.
Brad F Jacobs
+1  A: 

Well wouldn't your token be like a password a little bit? You could also redirect them to a special site, where they have to click a button spezified in the mail, to verify their identidy( or let them enter a pin from the mail), so you can be sure not to send all critical data per GET but per POST(important in a public place)

Hope I could help

Tokk
+2  A: 

That's a pretty common approach. The trick is to make sure the token is unique. I have used a GUID value in the past.

It all boils down to what is the risk vs the reward.

What is the risk that someone else could use that token to access your system. Since it's being sent via clear-text email the risk is probably moderate. (An attacker would have to be listening on their network or between you and their email host. Still not easy).

What's the reward. The attacker could submit a quote in the company's name. How bad is that? That is up to you.

Another risk I could see is if a company submits a quote and then later decides they don't want to honor it. They could just say they didn't submit it. Someone else must have done so in their name. Again, likelihood of this is probably not very high and could be dealt with in other ways.

Zippit
A: 

If they get some sort of daily email, you could generate a separate unique ID for each link. Or expire them after a specific period, and give them an update via email once every x days.

How big of a deal is it if someone guesses an ID or gets someone elses?

Also, why only 16 characters? They're not having to type it, so why not make it longer?

pseudocode

  $urlToken = md5( reverse(md5($key)) . md5( right(md5(key), 16) . left(md5(key),16) );

Would create a 64 character token.

Derrick
Are those reverse/right/left methods included in PHP? Also I agree on increasing the character count, as even though it's very unlikely that you'd get the same token generated with 16 characters, it's probably extremely unlikely you'd get the same one with 64 characters!
GSTAR
In php, it'd be md5( substr(md5($key), 16) . substr(md5($key), 0, 16)). If you're using MySQL as well, you can also use "select uuid()", which (at the database level) ensures you get a global unique id.
Derrick
A: 

You could try a uuid:

<?php

$uuid = `uuidgen`;

echo $uuid;

?>
Robin