Either by sending a code to SMS or Email, you are able to sign into your account without ever needing to or being able to add a password. Why has this become a thing recently?

  • ilinamorato@lemmy.world
    link
    fedilink
    arrow-up
    9
    ·
    18 hours ago

    They’re offloading authentication to your email provider. It’s basically quick and cheap oauth. I think it’s because they’re trying to avoid being a vector for a data breach.

    • rekabis@lemmy.ca
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      15 hours ago

      The irony being that putting all of a user’s eggs in one basket makes things far riskier for the user, and not less.

      • Jerkface (any/all)@lemmy.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        6 hours ago

        Smearing authentication credential data out across the entire Internet makes a sloppy user safer because the inevitable breeches that come with being sloppy are contained, but it increases the demands on a safe user while also increasing their attack surface. Though such a user does typically have a single point of failure in the form of their own sloppy password management.