Remix.run Logo
otter-in-a-suit 3 hours ago

I take passkeys over the unbearable cargo cult that follows LLM companies, namely companies' newly found obsession to "sign in via email".

Ideally optionally followed by a 2FA (naturally, via text, delivered straight to my Mac, even further diluting the questionable security of the whole exercise) and naturally, to be repeated every 2 days or so, since "stay logged in" is the biggest lie after "I've read and accepted the ToS".

Your phone (which is probably what, 80% of relevant traffic these days?) likely has a perfectly fine password manager built in. This "sign in via email" trend must be every scammer and phishers biggest dream come true...

PaulHoule 3 hours ago | parent [-]

Almost everything has supported email-based password reset since 90's for all the problems it entails.

I am looking at a new project that uses magic links sent by texts. I have been there and done that with authentication systems and that's good enough for a low stakes ludic activity.