
No, I don’t use it any longer. But from the late 1990s until the maturing of iCloud Keychain, I was guilty of often using the same random letters as my password. A web hosting company had generated it for my account in 1997 and my fingers’ muscle memory could type it rapidly.
I knew better — I did use something better on the most important credentials — but I still pretended. Most likely, you did too and our shared guilt has gotten us to a very bad place that makes everything worse for all of us.
Reusing passwords made sense when we needed fast access to accounts and had to depend on our brains as the source of how to get into them. But, in the era of password managers like iCloud Keychain or 1Password, continuing to reuse passwords is not only a bad idea, it isn’t even all that helpful. The beauty of a keychain is that modern ones will generate unique, secure passwords and store them right away — I now have dozens of passwords I’ve never even set my eyes upon for more than an instant. My cybersecurity is no longer dependent on my creativity or memory.
Even great passwords aren’t perfect though, so at some point we were visited upon by the curse of “2FA” — Two Factor Authentication — a necessary evil no matter how you craft your passwords. The most common form, one you probably encounter multiple times day, is the system where you get texted a six digit code as a second “factor” when you enter (or have your password manager enter) a password. Texting itself is insecure, but at least it adds a degree of difficulty if a hacker has to both crack a good password and sniff out your SMS texts to boot.
Even better has been the advent of authenticators. iCloud Keychain itself can generate authorization codes — as most password managers can — and those avoid the insecurity of text messaging and the inconvenience of being chained to one’s phone, too. On sites that let me use authcodes, I simply register the QR code it displays the first time I set it up and iCloud Keychain keeps a rolling (ever changing) code on the ready for when that specific site needs it.
Good and then, a few years back, the even better arrived: passkeys. These are, in essence, the rolling up of those password manager authcodes and passwords into a distinct third thing. Instead of combining a human readable password with some other thing, a much too hard to type in cryptographic key becomes the way to unlock everything in one swoop. Passkeys are secure enough they do not need a second factor at all.
If you’ve had the joy to use this modern ideal, supporting sites become a breeze to sign into. The login page automatically prompts the browser for the passkey if it exists and all we, as the users, have to do is tell the system it is ok to provide it. (On a Mac, for example, I get prompted to use my Touch ID finger print.) No muss, no fuss, more security.
That should be the end of the story, but, unfortunately, our long time laziness seems to have pushed providers a different way. I’ve noticed this plethora of options trying to move us beyond our worst password demons is quickly giving way to something worse and less secure, not this better promised land.
I noticed it first with Instacart or DoorDash. I stopped by to order something and it no longer prompted me for my password, but sent a “magic link” when I typed in my e-mail address or phone number. Given that my computer can nearly instantaneously fill in my password and give an authcode just as fast, waiting for an e-mail or SMS to come in is a massive slowdown not a shortcut.
And that’s when it works. When, as Claude tormented me with yesterday, a company’s mail server gets into a fight with one’s spam filter, it can become a huge ordeal just to log in. It should not take me twenty or thirty times longer — and way more effort — to get into Claude today than it did Amazon.com in 1995.
Worse, it isn’t as if this extra time and effort actually makes us more secure. Quite the opposite. This is the least secure form of 2FA possible, because it isn’t two factors at all: there is no password request, so the e-mail or text code becomes the sole factor. The sole factor sent via two notoriously insecure methods.
While it might be forgivable to use a less-than-secure method as a second factor after already getting a password, anyone who cares about security should already be trying to replace SMS or e-mail 2FA with authenticator app codes or passkeys wherever possible. Making those non-encrypted paths the login workflow isn’t just a regression, it is insanity.
If you’re terrible at remembering or saving passwords, this can feel convenient maybe you actually are glad when you go to DoorDash and it defaults to this infernal method. But, any password manager should cry out in anguish. And just think as more sites adopt this “feature:” a hacker cracks your e-mail and cracks everything.
Now, it is true most sites using magic links do still allow you to hit a button to login with a password (though that often still triggers the very same kind of login link, making the extra effort a worthless exercise), but in an era when most browsers support something so much better why are we going here? Passkeys make breaking into our entire digital life harder. Magic links are gifting the keys to the internet at large.
I wish I had the answer. I suspect it is because someone (perhaps correctly) thought it was better than large portions of their user base having the password “password.”
And so it is, by the tiniest jot. But such security laziness can be so easily redirected now in the passkey era — there is already a better way that is dead simple in a modern browser.
But no, now we wait for e-mails to meander across the internet with our personal information, stopping to smell the flowers as they go. If and when they show up, maybe we can still order food or login to our work accounts. If we even remember what it was we were trying to do.
Speaking of which, excuse me while I wait for another magic link to come in; it might show up today and I might remember what it was for.

Timothy R. Butler is Editor-in-Chief of Open for Business. He also serves as a pastor at Little Hills Church and FaithTree Christian Fellowship.
You need to be logged in if you wish to comment on this article. Sign in or sign up here.
Start the Conversation