Either by sending a code to SMS or Email, you are able to sign into your account without ever needing to or being able to add a password. Why has this become a thing recently?

  • fox2263@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    2 days ago

    Because the password still needs to be correct. What if the thief has your phone but no password

    • FreedomAdvocate
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      1 day ago

      If a thief already has your phone unlocked then nothing else matters, you’re fucked and all your accounts are compromised.

      • fox2263@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        18 hours ago

        There’s lots of factors for everything isn’t there. If a thief has your phone unlocked then yes you’re pretty much knackered

        • FreedomAdvocate
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 hours ago

          There’s no other factors when a thief already has your phone unlocked, which is why it’s a bad point to use against passworldess authentication in this argument.

      • fox2263@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        But they don’t have access to your email in this instance.

        If the thief has your email and password and phone then you’re SOL

        • FreedomAdvocate
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 day ago

          If they’ve got your phone with your 2FA they’ve also got your email on your phone lol

        • NewDark@lemmings.world
          link
          fedilink
          arrow-up
          2
          arrow-down
          1
          ·
          edit-2
          2 days ago

          If they don’t have email access, why is a passwordless magic link sent to an email bad then?

          • FreedomAdvocate
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 day ago

            The tech “enthusiasts” of Lemmy are really showing their arses in here lol. They have a “I took 2 semesters of computer science so I’m somewhat of an expert” level of understanding and mentality.

            There’s a reason most big tech companies are starting to move to passwordless logins. If 2FA is the ultimate protection about unauthorised access, the password is ultimately irrelevant - and given all we know about password reuse and data breaches, getting rid of them is a good thing.