Ask HN: Is it a bad idea to send OTP in URL link?
https://news.ycombinator.com/item?id=13019476I want to part ways with passwords, should I send my users a login link (via email, chat or sms) that contains an OTP? Is it safe? What known attacks are out there?