All mail + password + OTP works incredibly well, is secure and plays great with password managers.
Then something happened.
Because of single sign on, we could no longer have password field on the same page as the email.
Because of passkeys, now any login screen on a computer takes ages to go through. All french banks use a fancy keyboard with scrambled buttons, but then force you to have an 8 digit password...
And more recently, services ditch all login methods for a daily dose of "we've sent you a magic link that will keep you logged in for a day".
Claude authentication is so user hostile that I am now just waiting for my subscription to run out to ditch it, others have caught up anyway.
Does anybody working actively on security have an insight on how we got here? Are there any security benefits? Are there any user studies showing that what we currently use is somehow better?
eimrine•1m ago