I have 826 unique items stored in my password manager. Maybe three of them are cards. The others are all passwords, passkeys, authenticator keys and so on. It’s a lot. But it’s also secure. It’s been drilled into me to be secure – and it’s the sensible thing to do, anyway.
I have a unique password for every service. If a service supports 2FA, I’m using it: whether that’s a code, a text, an email or a passkey. I prefer it when it’s a passkey.
But have you noticed the trend of the magic email link? Or the we’ve sent you a code, just pop it in thing? It’s abhorent.
Firstly, don’t try to convince me that it’s secure. Monzo – who have used them for a very long time, to be fair – are convinced it’s more secure. No password means no password to steal; and doing anything with your account requires a second factor, like a PIN or a face.
But ultimately, anything that’s sending a link or a code to your email – as the only factor when signing in – is relying on your email account being secure. And that’s only partially where my annoyance sits.
These kinds of login systems are, of course, indirectly insisting that I go and open my email app. An app that I keep as secure as possible, because all kinds of organisations too lazy to implement proper login flows are using it as a means of authenticating me.
An app that, therefore, is a pain to open quickly because it’ll have to Face ID me, and has probably logged out and needs a password re-entering too. God forbid Microsoft Authenticator gets involved.
And don’t even get me started with the fact your login link has probably ended up in my spam folder, which means my email app will actively protect me by preventing me from clicking on your now slightly dodgy magic link.
And none of this is necessary. They’ve invented passkeys. We don’t need to do this farce anymore, if we ever did. There’s a great, convenient and secure solution. And you’re, instead, opting to send me a link over email. A code that I can copy and paste.
Magic links, codes sent to emails and the like as a single factor auth should not be allowed: stop relying on my email being secure, and implement passkeys.





