This is DANGEROUS advice. Email is typically one of the easiest channels to access. There are dozens of ways that someone can get access to your email, it shouldn't even remotely be considered secure.
For low security content it can be acceptable, I've used this method for email subscription centres before, however the only actions a user could do is manage their email subscription and thus it was considered to be acceptable. The idea that this method would be used for a SaaS product that is being paid for is mind-boggling.
Thats not to say it couldn't be used in multi-factor authentication, but tying the only authentication to email is creating a giant single point of failure from an insecure system with a shoddy security history.
Comments
This is DANGEROUS advice. Email is typically one of the easiest channels to access. There are dozens of ways that someone can get access to your email, it shouldn't even remotely be considered secure.
For low security content it can be acceptable, I've used this method for email subscription centres before, however the only actions a user could do is manage their email subscription and thus it was considered to be acceptable. The idea that this method would be used for a SaaS product that is being paid for is mind-boggling.
Thats not to say it couldn't be used in multi-factor authentication, but tying the only authentication to email is creating a giant single point of failure from an insecure system with a shoddy security history.