Lately, the process of accessing apps and websites has grown dizzying. “I’m in password hell,” a colleague confided to me recently. “Every login attempt is playing the lottery.” The problem is not just the sheer number of digital accounts, all of which require their own password, ideally unique and unguessable (which usually also means un-memorizable). It’s the pileup of solutions to that problem: all of the different layers of software offering to remember your passwords, the six-digit codes sent to your phone, the authenticator apps, the passkeys.



There’s also websites that for some reason only request a username/e-mail and then send you a one time login code, requiring me to open my e-mail program instead of having a one click login with my password manager…
There are so many downsides to this method compared to a password manager too. There’s no encryption, email itself is a minefield when it comes to decent security practices, and I’ve often been stuck waiting for a login link to arrive before I can actually use whatever I was trying to manage.
It is literally insane. The codes/links usually only work for 10-15 minutes. If the mail fails the RFC 5321 recommends a retry interval of at least 30 minutes (for up to 4 to 5 days).
These drive me up the wall. If you email me a signin code at login and offer a “forgot password” reset by email, then the password is cosmetic. Just get rid of it ffs.