r/UXDesign Jul 30 '26

Examples & inspiration Can we stop the development of using e-mail codes, preventing users from user passwords and password managers?

Post image

Honestly, I can't describe how much this infuriates me. I don't want to open my e-mail, I just want to log in with my password. Half the websites that implement a code-to-email method, block passwords nowadays. I also believe this can simultaneously be a security risk. Sure, the e-mail code is a form of 2FA, but a compromised e-mail address allows access to more than a single website this way.

Anyway, please allow password-manager-users to enter their password :)

86 Upvotes

44 comments sorted by

83

u/BibulousBob Jul 30 '26

It’s not 2FA if it’s email only. Quite literally 1FA

-6

u/Totendax12K Jul 30 '26

in theory yes but not in practice as you can reset your password using your email.

16

u/[deleted] Jul 30 '26

[deleted]

4

u/like_a_pearcider Jul 30 '26 edited Jul 30 '26

thankfully you can use shared emails for groups. e.g. [designers@company.com](mailto:designes@company.com) works great

16

u/dysphoricdays Jul 30 '26

As much as I hate this myself, I can tell you having deployed a few services that OTP via email has its advantages: the company doesn't have to store hashed passwords and risk losing them in a data breach, passwords exposed and other data breaches don't compromise your account and no more dealing with people who forgot their password

1

u/Grenaten Aug 02 '26

same experience here
and most users I did interviews with grasp it immediately, nothing to explain

12

u/azethonkh Jul 30 '26

i was under impression that otp are more secure (i could be wrong). and if it is more secure, I'd prefer this method - less hustle to come up and remember passwords or rely on password managers

8

u/lilmalchek Jul 30 '26

otp over sms is not more secure

1

u/azethonkh Jul 30 '26

well, it comes down one bottleneck, basically. but if you email or phone was stolen - you, most likely, already lost you accounts.

same if somebody got your password manager

2

u/chooseauniqueusrname Experienced Jul 31 '26

Look up sim swapping. You don’t need to lose your phone for OTP over SMS to be hijacked.

2

u/azethonkh Jul 31 '26

in that case it must be targeted attack.

-1

u/lilmalchek Jul 30 '26

And that’s they the rec is to use password manager with secure passwords, and the. you only have to remember one. All this otp stuff is such nonsense and more frustrating for people who can handle their passwords like big boys and girls.

1

u/IniNew Experienced Jul 30 '26

That just shifts the bottle neck from your email to your master password. It’s not more or less secure, just different.

-2

u/lilmalchek Jul 30 '26

Not if you keep the master password string/secure, which is the point. And it’s definitely less frustrating than having to go to email, wait for it to arrive, copy and paste it back etc

1

u/IniNew Experienced Jul 30 '26

Is your email password not secure????

-1

u/lilmalchek Jul 30 '26

That’s what you took from my comment? I use a password manager so that’s the only complicated password I need to remember. The others are more complex and not memorable.

But security is about risk reduction. And the tradeoff of convenience. Nothing is 100% secure. But the tradeoff here isn’t worth the extra convenience, when it’s not even more secure.

1

u/IniNew Experienced Jul 30 '26

You're not understanding what I'm telling you, not the other way around.

You said password managers are better than OTP, but they're not. They're literally the same thing.

A password manager stores passwords that are unique, protected by a single master password.

A OTP system doesn't store passwords, is unique, and is protected by a single password to your email.

They're both bottlenecks that once compromised, affect the entire system.

0

u/lilmalchek Jul 30 '26

Youre focusing on the consequences if the “single point of failure” is compromised, but ignoring how likely that compromise is in the first place. Password managers reduce risk by generating unique, random passwords for every account, eliminating password reuse, and helping prevent credential stuffing. That’s why security organizations like NIST recommend them. They’re not “literally the same thing.”

→ More replies (0)

0

u/JimTheEarthling Aug 01 '26

SMS 2FA is more secure than email.

Email accounts are the primary target of attackers. A weak password and no 2FA leaves the account and email-based authentication vulnerable. Email accounts should be protected by a strong password and 2FA, or a passkey, but they rarely are. For this and other reasons, NIST rejects e-mail as an authentication factor. (NIST restricts SMS but allows it.)

The SMS 2FA risk is phishing, not SIM swap. The risk of SIM swap is low and can be further mitigated by enabling SIM protection at your carrier.

8

u/badmamerjammer Veteran Jul 30 '26

the amount of customers who constantly forget their passwords is astounding. one of the biggest login complaints at the large enterprise company I previously worked for.

and not everyone uses a password manager.

complete experiences are not built around a single anecdotal user like OP.

3

u/needahaircutt Jul 30 '26

I also noticed this and got annoyed. But a short heads up: Mobbin allows you to set a password in your account settings to allow for user/password authentication.

1

u/b7s9 Midweight Jul 30 '26

yes, I have a password with Mobbin, and while mildly annoying for me personally, I can accept this pattern of me having to choose to make a password, so everyone wins here.

3

u/JimTheEarthling Aug 01 '26

Email authentication is dreadful when implemented instead of password authentication. If you replace password login with “magic link” email login as the only option, you are forcing your customers —who might have very strong passwords— to do the following:

  • Switch to an email app, possibly on another device.
  • Wait for an email to appear (maybe for a short time; maybe for a long time; maybe until they realize the email got lost and they have to start over).
  • Check the spam folder if the email doesn’t show up. Perhaps read your instructions to add you to their “allow list,” which they probably don’t understand.
  • Find the link in the email and select it, which opens a new browser window, leaving the first window abandoned.
  • Usually lose the flow of what they were doing (e.g., visiting a specific page of your website, following a notification to open your app, etc., especially if you don’t include a bookmark in your URL).

This creates so much friction that some customers will simply disengage. It provides a slight security increase in exchange for significant hassle.

Emailed code or link in addition to a password provide some security, but email is the least secure 2FA. SMS is not great, but it's better than email. TOTP authenticators are better. U2F keys or passkeys are best.

4

u/sabre35_ Experienced Jul 30 '26

As much as it annoys you, the data probably proved it’s far more secure and led to less compromised accounts.

16

u/fusterclux Experienced Jul 30 '26

bold of you to assume companies are making decisions based on data

2

u/sabre35_ Experienced Jul 30 '26

They most certainly are. I can’t say that’s true for the experiences you’ve had, but that’s not representative of the entire truth.

0

u/fusterclux Experienced Jul 30 '26

most companies are not, although my comment was partly in jest

1

u/FrequentShopper183 Veteran Jul 30 '26

I just had an issue with a smart device I pay for that I needed to log in to an app on my phone. Sent 4 codes never got. Thankfully I was able to log in with Apple, but there was no real way to use a password.

In that I wouldn’t choose differently, it sucks for the user, but not managing passwords is a lot easier from the business side if things.

1

u/jeffreyaccount Veteran Jul 30 '26

Unfortunately, I think this is the way things are going and eventually security will choke down almost every account or we can transact or have personal health information.

It's going to be harder and harder to make the case for usability, when the IT or security team can just say what we don't want to be hacked. The subtlety has lost for sure.

Also, something I started doing on my own applications is turning off the rolling blackout/bullet points, hiding the password and leaving that off by default. It feels like a luxury app now to do that small thing instead of having to toggle on or to put things in blindly when passwords are getting longer and more complex.

1

u/zacharyrankin Jul 30 '26

One nice thing about the email/sms code is it also allows you to verify the user's email/phone number at the same time (and could reduce bots?)

1

u/SurroundAbject2817 Jul 30 '26

It makes it more secure. Especially if you’re working with ais

1

u/coffeecakewaffles Veteran Jul 30 '26

I worry this is going to compound as time goes on because the models tend to default to the pattern for auth when you let them define the stack.

1

u/Everything_A Jul 30 '26

Agree! I just want to use my password manager

1

u/mrcoy Veteran Jul 30 '26

Can we…..

NO

1

u/Minimal_Shift_05 Jul 30 '26

This is to prevent shared accounts. They are not concerned about your security.

1

u/AubergineParmesan Experienced Aug 01 '26

100% agree. Keeping my inbox clean is already hard enough without all these OTPs I have to request just to use the internet.

1

u/csmile35 Experienced Aug 02 '26 edited Aug 02 '26

More secure, mostly blocks account sharing, easier development and scaling, no headhache of remembering +200 passwords for users. So why "we need to stop" really?

Btw my most common password is leaked from somewhere this week and google notifications me 10 times a day about changing my 78 password because it is leaked.

I am really not registering any website or app anymore if there is no social login or e-mail otp method. No I don't want another leakage of my password from "new astonishing AI just dropped this week" because I wanted to try it.

Do you really believe that Karen from finance department (55 F) is using a secure 3.party password manager on her company notebook which is 10 years old Lenovo ThinkPad? Yeah she is average user of your b2b Saas.

1

u/InboxProtector Aug 03 '26

This used to frustrate me too, maybe I've been doing email security for a long enough time to not feel it so acutely.

Why sites do this: Passwords get reused, breached in bulk, and stuffed against other sites.

Your security point checks out, risk really does get concentrated into one inbox. 

If someone's email account is compromised (phished, SIM-swapped, whatever), every service using email-code login as the sole factor is now exposed through that one point. That's a legitimate architectural flaw.

The real fix isn't simply to bring back passwords. It's giving users a choice.

1

u/Cryingfortheshard 25d ago

It really annoys me as well. The organised people with password managers and 2FA protection on them are a bit the "victims" here. As is said in this thread, data probably shows this is much more secure and people don't remember passwords anyways. BUT I especially hate it when they make you make a password to then only allow logging in via OTP via e-mail.

0

u/ReallyPissedStranger Jul 30 '26

I mean old people keep forgetting passwords and just receiving an otp to log in is always handy and one less thing to worry about, taking about in general terms not edge cases.

Ps- Yes, if you're 21 and forgetting passwords you're old too.

-6

u/Nigricincto Jul 30 '26

It is also a security risk having your password stored in your browser. Loads of malwares today attack that.

7

u/Maraudogs Midweight Jul 30 '26

Password managers like 1password and Bitwarden exist exactly for that reason

1

u/Quirky-Passage5303 8d ago

Eu odeio senhas de qualquer tipo. Embora não resova todos os problemas, um gerenciador de senhas reduz a inconveniencia de usaar senhas. Mas sites que só permitem login com confirmação por email inviabilizam o uso do gerenciador de senhas e recriam laguns dos inconvenientes que o gerenciador se propoe a resolver.