No explicit backup, but I think you're also assuming Google-level lack of customer service. If someone contacted me telling me they lost control of their email, there's a lot of steps I could take to help them out short of telling them tough luck and them never being able to access their account again.
back
2 comments
True. And I don't want to be overly pedantic with the implementation details.
I like your proposal to remove passwords and prevent phising in general and I'm trying to give some honest feedback on what I think is wrong with this auth system.
The title of this post is "Tell me why this auth system is a bad idea", after all, not "Tell me the good parts of this auth system" ;)
I guess a question I would have for you is: name a few companies to which you would like to pitch this auth system. (e.g. your first few customers if you turned this into a startup or something)
This actually strikes me as a quite dangerous mindset! A lot of "hacked" accounts happen when someone tricks customer support. How, exactly, would you verify the customer's legitimacy?
By asking them their mother’s maiden name, of course!